@angular/router@12.2.16

Angular - the routing library

  • latest version

    22.2.1

  • latest non vulnerable version

  • first published

    10 years ago

  • latest version published

    2 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @angular/router package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Allocation of Resources Without Limits or Throttling

    Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the URL parsing of matrix parameters and child outlet names, which stores them as keys on plain JavaScript objects, so a numeric string key leads V8 to convert the object to a dense array backing store sized to the largest index, amplifying an 11 byte segment into 20 to 25 KB of heap. An attacker can exhaust the old space heap of a server side rendering worker and crash it with a JavaScript heap out of memory error, by sending requests whose paths repeat numeric matrix parameters, such as /a;990;2522/a;990;2522/, with 12 to 22 concurrent 8 KB paths sufficient against a 256 to 512 MiB worker. This requires server side rendering on Node.js with user controlled URLs reaching the router, so client side single page applications are unaffected, and it depends on no reverse proxy filtering semicolons or capping path segments ahead of the application.

    How to fix Allocation of Resources Without Limits or Throttling?

    Upgrade @angular/router to version 20.3.32, 21.2.24, 22.2.0 or higher.

    <20.3.32>=21.0.0 <21.2.24>=22.0.0 <22.2.0