22.2.1
10 years ago
2 days ago
Known vulnerabilities in the @angular/router package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the URL parsing of matrix parameters and child outlet names, which stores them as keys on plain JavaScript objects, so a numeric string key leads V8 to convert the object to a dense array backing store sized to the largest index, amplifying an 11 byte segment into 20 to 25 KB of heap. An attacker can exhaust the old space heap of a server side rendering worker and crash it with a JavaScript heap out of memory error, by sending requests whose paths repeat numeric matrix parameters, such as How to fix Allocation of Resources Without Limits or Throttling? Upgrade | <20.3.32>=21.0.0 <21.2.24>=22.0.0 <22.2.0 |