Skip to content

chore(deps): update dependency @angular/router to v22.2.0 [security] - #523

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/npm-angular-router-vulnerability
Oct 4, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/npm-angular-router-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@angular/router (source) 22.1.7 → 22.2.0 age adoption passing confidence

Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters

CVE-2026-101896 / GHSA-ff3f-86qr-9cv3

More information

Details

A denial of service (DoS) vulnerability was identified in @angular/router when Server-Side Rendering (SSR) is enabled on Node.js (V8).

When @angular/router parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (Record<string, string>). When matrix parameter names or outlet names are numeric strings (such as /a;990;2522), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.

Under V8's internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (HOLEY_ELEMENTS) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like 990 followed by 2522) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment.

Because each segment in a URL path allocates its own independent parameters object, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately ~350x.

Impact

Successful exploitation allows an unauthenticated remote attacker to exhaust the Node.js old-space heap with modest request volume, terminating the SSR worker with an unrecoverable JavaScript heap out of memory fatal error and causing a Denial of Service.

  • High Amplification: A single 11-byte segment (/a;990;2522) consumes ~20 KB–25 KB of V8 heap.
  • Low Concurrency Required:
    • With 8 KB request paths (~740 segments, within default Nginx 8 KB buffer limits), as few as 12–22 concurrent requests crash a 256 MiB–512 MiB Node.js SSR worker.
    • With smaller 1 KB–2 KB request paths (~90–180 segments), a burst of ~50–100 concurrent requests achieves the same heap exhaustion.
  • Client-side SPAs Unaffected: Pure client-side Angular applications (Single Page Applications without SSR) are not vulnerable, as local browser memory consumption does not cross a security boundary.
Attack Preconditions & Vulnerable Configurations

An application is affected only if all of the following conditions are met:

  • SSR Enabled: The application runs in a Server-Side Rendering environment powered by Node.js / V8.
  • Direct Router Parsing: User-controlled request URLs are parsed by @angular/router during SSR.
  • No Reverse-Proxy Semicolon/Segment Filtering: Upstream reverse proxies (Nginx, Cloudflare, ALB) forward URLs containing semicolons (;) and multiple path segments without stripping or rejecting them.
Exploit Payload Example

An attacker sends concurrent HTTP requests with repeated numeric matrix parameters:

GET /a;990;2522/a;990;2522/a;990;2522/... HTTP/1.1
Host: example.com

Even with paths under 2 KB, overlapping requests during SSR will rapidly consume the V8 heap until the process crashes.

Patches

The issue is resolved by updating @angular/router to enforce V8 dictionary elements storage (setUrlDerivedKey) for numeric URL-derived keys (index >= 32). This prevents V8 from allocating oversized contiguous array backing stores while preserving route matching, parameter values, and component input bindings.

  • 22.2.0
  • 21.2.24
  • 20.3.32
Workarounds & Mitigations

If you cannot immediately upgrade to a patched version, apply one of the following mitigations at your edge or reverse proxy:

  1. Block or Sanitize Matrix Parameters at the Reverse Proxy:
    Configure your reverse proxy (e.g., Nginx, Cloudflare, or AWS WAF) to reject or strip semicolons (;) in request paths before forwarding requests to the Angular SSR service:
    # Nginx example: reject requests containing matrix parameters
    if ($uri ~* ";") {
        return 400;
    }
  2. Enforce Strict Path Segment Limits:
    Reject requests with excessive path depth (e.g., more than 20–30 segments).
  3. Increase Node.js Old Space:
    Increase --max-old-space-size (e.g., to 2048 or 4096 MB) to increase the concurrency threshold required to exhaust memory, though this does not fully eliminate the vulnerability under sustained traffic.

Severity

  • CVSS Score: 8.2 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

angular/angular (@​angular/router)

v22.2.0

Compare Source

compiler
Commit Type Description
48a0fd6e8a feat allow template to access private props
a4f1a94948 fix do not encapsulate nested selectors if parent contains ::ng-deep
d0d7f57e08 fix scope nested CSS rules
compiler-cli
Commit Type Description
312e1d8089 feat add strictUnclaimedEventNames option to catch misspelled output bindings
7d9f55da11 feat scope type-checking of keyed defer blocks
2e2c426e76 fix deduplicate deferred imports across multiple blocks
core
Commit Type Description
f6afb807c1 feat add ErrorBoundary programmatic APIs (#​70463)
05c4d5a835 feat add utility for testing directives
bd9b45b5cc feat allow reading Injector from a view or content query
91a2bf8425 feat support annotations in WebMCP tool declarations
af2c7e386d fix cancel leave animations in nested views during list reordering
de5889ec4f fix support function and signal bindings in animate.enter and animate.leave
a8233232f5 fix update FakeNavigation to match WHATWG HTML spec
forms
Commit Type Description
d5e8b1ef7a feat allow permanent hidden fields in signal forms
6e299da8cf feat hard-code readOnlyHint and untrustedContentHint for WebMCP implicit signal forms
language-service
Commit Type Description
f4a5650ed9 feat add support for @boundary blocks (#​70463)
router
Commit Type Description
2720362818 feat add containsTree as public API
b65dea4f03 feat allow throwing RedirectCommand to trigger redirects
3064f3f1dc feat expose router resources in public API
7137a41223 feat stabilize auto cleanup injectors feature
094bce9e3d fix determine blocking state solely by resource loading status
6f5a4a06c2 fix expose reload method on ActivatedRoute resources
2c6c67bee6 fix maintain frozen state on rollback until resource loading completes
2dcdf9aae6 fix mark router_resource module-level symbols as side-effect free

v22.1.8

Compare Source

common
Commit Type Description
850db9d999 fix remove abort listener on the abort path too in httpResource
compiler
Commit Type Description
4e5f4c38a7 fix add return type to pure functions
02e83dc288 fix avoid hitting TypeScript limits if template has many translations
024ebe668c fix do not copy expression type into output AST variables
b3c5824bd6 fix guard unverified ctor parameter types in class metadata
compiler-cli
Commit Type Description
fe671d9024 fix output function return types in linker
core
Commit Type Description
d7d5401cd5 fix don't use plain objects as maps for jsaction data
c3e8f29b3f fix ensure references are cleared from idle scheduler
9b854f6e76 fix loosen return types for arrow functions in generated code
cfa8967683 fix wait for app stability before cleaning up dehydrated views
forms
Commit Type Description
78c7ab3926 fix create controls before listeners
platform-server
Commit Type Description
330083f250 fix preserve Unicode whitespace in ServerXhr URLs
router
Commit Type Description
2cab6f5964 fix avoid dense elements allocation for numeric URL keys

Configuration

📅 Schedule: (in timezone Asia/Shanghai)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) October 1, 2026 08:47
@socket-security

socket-security Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​angular/​router@​22.1.7 ⏵ 22.2.0100 +1100 +1677 +198100

View full report

@renovate
renovate Bot force-pushed the renovate/npm-angular-router-vulnerability branch 10 times, most recently from bb2918c to bbc6e97 Compare October 4, 2026 13:07
@renovate
renovate Bot force-pushed the renovate/npm-angular-router-vulnerability branch from bbc6e97 to 137eae8 Compare October 4, 2026 14:05
@renovate
renovate Bot merged commit c512647 into main Oct 4, 2026
9 checks passed
@renovate
renovate Bot deleted the renovate/npm-angular-router-vulnerability branch October 4, 2026 14:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant