In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.
Start learningUpgrade @angular/router to version 20.3.32, 21.2.24, 22.2.0 or higher.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the URL parsing of matrix parameters and child outlet names, which stores them as keys on plain JavaScript objects, so a numeric string key leads V8 to convert the object to a dense array backing store sized to the largest index, amplifying an 11 byte segment into 20 to 25 KB of heap. An attacker can exhaust the old space heap of a server side rendering worker and crash it with a JavaScript heap out of memory error, by sending requests whose paths repeat numeric matrix parameters, such as /a;990;2522/a;990;2522/, with 12 to 22 concurrent 8 KB paths sufficient against a 256 to 512 MiB worker. This requires server side rendering on Node.js with user controlled URLs reaching the router, so client side single page applications are unaffected, and it depends on no reverse proxy filtering semicolons or capping path segments ahead of the application.
This vulnerability can be avoided by configuring the reverse proxy to reject or strip semicolons in request paths, or to enforce a limit of 20 to 30 path segments.