Skip to content

[deps]: Update @angular/router to v21.2.24 [SECURITY] - #240

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-angular-router-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-angular-router-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
@angular/router (source) 21.2.17 → 21.2.24 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters

CVE-2026-101896 / GHSA-ff3f-86qr-9cv3

More information

Details

A denial of service (DoS) vulnerability was identified in @angular/router when Server-Side Rendering (SSR) is enabled on Node.js (V8).

When @angular/router parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (Record<string, string>). When matrix parameter names or outlet names are numeric strings (such as /a;990;2522), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.

Under V8's internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (HOLEY_ELEMENTS) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like 990 followed by 2522) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment.

Because each segment in a URL path allocates its own independent parameters object, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately ~350x.

Impact

Successful exploitation allows an unauthenticated remote attacker to exhaust the Node.js old-space heap with modest request volume, terminating the SSR worker with an unrecoverable JavaScript heap out of memory fatal error and causing a Denial of Service.

  • High Amplification: A single 11-byte segment (/a;990;2522) consumes ~20 KB–25 KB of V8 heap.
  • Low Concurrency Required:
    • With 8 KB request paths (~740 segments, within default Nginx 8 KB buffer limits), as few as 12–22 concurrent requests crash a 256 MiB–512 MiB Node.js SSR worker.
    • With smaller 1 KB–2 KB request paths (~90–180 segments), a burst of ~50–100 concurrent requests achieves the same heap exhaustion.
  • Client-side SPAs Unaffected: Pure client-side Angular applications (Single Page Applications without SSR) are not vulnerable, as local browser memory consumption does not cross a security boundary.
Attack Preconditions & Vulnerable Configurations

An application is affected only if all of the following conditions are met:

  • SSR Enabled: The application runs in a Server-Side Rendering environment powered by Node.js / V8.
  • Direct Router Parsing: User-controlled request URLs are parsed by @angular/router during SSR.
  • No Reverse-Proxy Semicolon/Segment Filtering: Upstream reverse proxies (Nginx, Cloudflare, ALB) forward URLs containing semicolons (;) and multiple path segments without stripping or rejecting them.
Exploit Payload Example

An attacker sends concurrent HTTP requests with repeated numeric matrix parameters:

GET /a;990;2522/a;990;2522/a;990;2522/... HTTP/1.1
Host: example.com

Even with paths under 2 KB, overlapping requests during SSR will rapidly consume the V8 heap until the process crashes.

Patches

The issue is resolved by updating @angular/router to enforce V8 dictionary elements storage (setUrlDerivedKey) for numeric URL-derived keys (index >= 32). This prevents V8 from allocating oversized contiguous array backing stores while preserving route matching, parameter values, and component input bindings.

  • 22.2.0
  • 21.2.24
  • 20.3.32
Workarounds & Mitigations

If you cannot immediately upgrade to a patched version, apply one of the following mitigations at your edge or reverse proxy:

  1. Block or Sanitize Matrix Parameters at the Reverse Proxy:
    Configure your reverse proxy (e.g., Nginx, Cloudflare, or AWS WAF) to reject or strip semicolons (;) in request paths before forwarding requests to the Angular SSR service:
    # Nginx example: reject requests containing matrix parameters
    if ($uri ~* ";") {
        return 400;
    }
  2. Enforce Strict Path Segment Limits:
    Reject requests with excessive path depth (e.g., more than 20–30 segments).
  3. Increase Node.js Old Space:
    Increase --max-old-space-size (e.g., to 2048 or 4096 MB) to increase the concurrency threshold required to exhaust memory, though this does not fully eliminate the vulnerability under sustained traffic.

Severity

  • CVSS Score: 8.2 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

angular/angular (@​angular/router)

v21.2.24

Compare Source

router
Commit Type Description
03872a80bc fix avoid dense elements allocation for numeric URL keys

v21.2.23

Compare Source

platform-server
Commit Type Description
fc2e8fbc0b fix update domino to latest version

v21.2.22

Compare Source

platform-server
Commit Type Description
5aa6d97deb fix avoid stripping unicode whitespace during url resolution
73d8bbd27c fix update domino to latest version

v21.2.21

Compare Source

platform-browser
Commit Type Description
c19a36c2fb fix disallow event handler attributes in Meta

v21.2.20

Compare Source

core
Commit Type Description
6afe6fa781 fix sanitize host bindings on concrete hosts
http
Commit Type Description
fec5977df4 fix match header values exactly when deleting
e33d69a71c fix preserve immutability of materialized clones
caf616670f fix run root interceptors in the terminal request chain

v21.2.19

Compare Source

compiler
Commit Type Description
e2660c3dee fix disallow i18n event attributes
7b884f585a fix restrict possible event handler check to property names longer than 2 characters
http
Commit Type Description
948a8d6831 fix distinguish repeated transfer cache params
9949dccce1 fix enable xsrf for root-provided HttpClient
platform-server
Commit Type Description
f34a93c946 fix update domino to latest version

v21.2.18

Compare Source

compiler-cli
Commit Type Description
8d22cc953b fix update babel dependencies to latest v7
core
Commit Type Description
6bcce117fb fix avoid caching missing locale data
5a693bafcd fix reject dynamic script host elements
http
Commit Type Description
91df739b80 fix prevent caching of responses with Set-Cookie headers
service-worker
Commit Type Description
1804f73bec fix preserve referrer in asset requests
e86c31bf26 fix preserve referrer policy in asset requests

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner October 5, 2026 02:53
@renovate renovate Bot added the security label Oct 5, 2026
@renovate
renovate Bot requested a review from Banrion October 5, 2026 02:53
@renovate renovate Bot added the security label Oct 5, 2026
@renovate
renovate Bot requested a review from a team October 5, 2026 02:53
@renovate

renovate Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor Author

⚠️ Artifact update problem

Renovate failed to update an artifact related to this branch. You probably do not want to merge this PR as-is.

♻ Renovate will retry this branch, including artifacts, only when one of the following happens:

  • any of the package files in this branch needs updating, or
  • the branch becomes conflicted, or
  • you click the rebase/retry checkbox if found above, or
  • you rename this PR's title to start with "rebase!" to trigger it manually

The artifact failure details are included below:

File name: ui/package-lock.json
npm warn Unknown env config "store". This will error in a future major version of npm. See `npm help npmrc` for supported config options.
npm error code ERESOLVE
npm error ERESOLVE unable to resolve dependency tree
npm error
npm error While resolving: @bitwarden/splunk-ui@1.0.0
npm error Found: @angular/common@21.2.17
npm error node_modules/@angular/common
npm error   @angular/common@"21.2.17" from the root project
npm error
npm error Could not resolve dependency:
npm error peer @angular/common@"21.2.24" from @angular/router@21.2.24
npm error node_modules/@angular/router
npm error   @angular/router@"21.2.24" from the root project
npm error
npm error Fix the upstream dependency conflict, or retry this command with --force or --legacy-peer-deps to accept an incorrect (and potentially broken) dependency resolution.
npm error
npm error
npm error For a full report see:
npm error /runner/cache/others/npm/_logs/2026-10-05T19_56_37_917Z-eresolve-report.txt
npm error A complete log of this run can be found in: /runner/cache/others/npm/_logs/2026-10-05T19_56_37_917Z-debug-0.log

AlexRubik added a commit that referenced this pull request Oct 6, 2026
Moves all framework packages to 21.2.24 together, which also fixes
CVE-2026-101896 in @angular/router (supersedes the per-package
Renovate PR #240).

[PM-44515]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants