CVE-2026-101895

Denial of Service
Affects
Angular
in
Angular
No items found.
Versions
>=5.0.0-beta.6 <=19.2.25, >=20.0.0 <20.3.31, >=21.0.0 <21.2.23, >=22.0.0 <22.1.6

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Angular is a TypeScript-based web development platform for building scalable single-page and server-side rendered applications. It provides a modular architecture, powerful dependency injection, and built-in tools for building modern, performant, and maintainable applications across web, mobile, and desktop environments.

A Denial of Service (DoS) vulnerability (CVE-2026-101895) has been identified in Angular's Platform Server, which allows unauthenticated attackers to trigger an infinite loop during server-side rendering through an incomplete DOCTYPE declaration and can lead to the Node.js server process being pinned at full CPU utilization and unable to respond to any further requests.

Per OWASP: The Denial of Service (DoS) attack is focused on making a resource (site, application, server) unavailable for the purpose it was designed. There are many ways to make a service unavailable for legitimate users by manipulating network packets, programming, logical, or resources handling vulnerabilities, among others. If a service receives a very large number of requests, it may cease to be available to legitimate users. In the same way, a service may stop if a programming vulnerability is exploited, or the way the service handles resources it uses.

This issue affects multiple versions of Angular.

Details

Module Info

  • Product: Angular
  • Affected packages: @angular/platform-server
  • Affected versions:
    • >=5.0.0-beta.6 <=19.2.25
    • >=20.0.0 < 20.3.31
    • >=21.0.0 < 21.2.23
    • >=22.0.0 < 22.1.6
  • GitHub repository: https://github.com/angular/angular
  • Published packages: https://www.npmjs.com/package/@angular/platform-server
  • Package manager: npm
  • Fixed in:
    • OSS Angular v20.3.31, v21.2.23 and v22.1.6
    • Angular NES v19.2.30, v18.2.26, v17.3.26, v16.2.26, v15.2.24, v14.3.15, v13.4.17, v12.3.11, v11.2.29, v10.2.21, v9.1.27, v8.2.27, v7.2.28, v6.1.23, v5.2.22

Vulnerability Info

This High-severity vulnerability is found in the @angular/platform-server package in multiple published versions of Angular. The underlying defect is in domino, the DOM emulation dependency that Platform Server uses to serialize rendered HTML on the server.

A Denial of Service (DoS) vulnerability exists in @angular/platform-server's DOM emulation parser (domino). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF (such as <!DOCTYPE html ), the HTML parser enters an infinite synchronous loop, pegging CPU utilization at 100% and completely freezing the Node.js server process.

In Angular Server-Side Rendering (SSR), @angular/platform-server uses domino to parse and sanitize HTML bound through template bindings (such as [innerHTML]) or manipulated via DOM APIs.

In Domino's HTML parser (lib/HTMLParser.js), tokenizer states that specify fixed lookahead, such as after_doctype_name_state (lookahead = 6), rely on the state handler function to explicitly advance the character index pointer (nextchar). While branches for whitespace, >, and keyword matching advance nextchar, the EOF branch (case -1: // EOF) emitted doctype and EOF tokens without advancing nextchar or transitioning out of the state. Because nextchar remained unchanged pointing to the EOF marker character (\uFFFF), the scanner loop (while (nextchar < numchars)) repeatedly re-invoked after_doctype_name_state with codepoint = EOF indefinitely. In Node.js's single-threaded runtime, this synchronous loop starves the event loop entirely.

The vulnerability is reachable in any Angular SSR application where untrusted user input is bound to [innerHTML], interpolated into markup, or sanitized on the server. Successful exploitation allows an unauthenticated remote attacker to cause an immediate Denial of Service (DoS) by sending a payload containing an incomplete DOCTYPE (e.g., <!DOCTYPE html ). The Node.js SSR process locks up at 100% CPU and ceases responding to all concurrent and subsequent HTTP requests.

Mitigation

Angular versions prior to 20 were already End-of-Life when this CVE was published and will not receive any updates to address this issue. For more information see here.

Users of the affected components should apply one of the following mitigations:

  • Migrate affected applications to a patched version of Angular.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support.
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2026-101895
PROJECT Affected
Angular
Versions Affected
>=5.0.0-beta.6 <=19.2.25, >=20.0.0 <20.3.31, >=21.0.0 <21.2.23, >=22.0.0 <22.1.6
NES Versions Affected
Published date
September 29, 2026
≈ Fix date
September 16, 2026
Category
Denial of Service
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Angular
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.