Allocation of Resources Without Limits or Throttling Affecting @angular/router package, versions <20.3.32>=21.0.0 <21.2.24>=22.0.0 <22.2.0


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-ANGULARROUTER-20361514
  • published1 Oct 2026
  • disclosed30 Sept 2026
  • creditUnknown

Introduced: 30 Sep 2026

NewCVE-2026-101896  (opens in a new tab)
CWE-770  (opens in a new tab)

How to fix?

Upgrade @angular/router to version 20.3.32, 21.2.24, 22.2.0 or higher.

Overview

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling in the URL parsing of matrix parameters and child outlet names, which stores them as keys on plain JavaScript objects, so a numeric string key leads V8 to convert the object to a dense array backing store sized to the largest index, amplifying an 11 byte segment into 20 to 25 KB of heap. An attacker can exhaust the old space heap of a server side rendering worker and crash it with a JavaScript heap out of memory error, by sending requests whose paths repeat numeric matrix parameters, such as /a;990;2522/a;990;2522/, with 12 to 22 concurrent 8 KB paths sufficient against a 256 to 512 MiB worker. This requires server side rendering on Node.js with user controlled URLs reaching the router, so client side single page applications are unaffected, and it depends on no reverse proxy filtering semicolons or capping path segments ahead of the application.

Workaround

This vulnerability can be avoided by configuring the reverse proxy to reject or strip semicolons in request paths, or to enforce a limit of 20 to 30 path segments.

CVSS Base Scores

version 4.0
version 3.1