Angular Patches Four Server-Side Rendering Advisories in Eight Days, Three Rated High, Across Versions 20, 21 and 22
Angular's maintainers published four GitHub advisories between September 23 and October 1 covering router and platform-server flaws in server-side rendering, three rated High.
Editor's Note ·
- Correction:
- The article quotes the RouterLink advisory (GHSA-57xq-rjx2-v5xh) as "permanently pinning the UrlTree and its associated query parameter dictionary in the heap until the SSR response completed." The advisory's wording is "the computed signal permanently pinned the UrlTree and its associated query parameter dictionary in the heap until the SSR response completed."
- Correction:
- The article says the September 23 advisory describes raising Node.js's --max-old-space-size as a temporary measure, in contrast to the empty-path outlet advisory. The September 23 advisory does not use that word; it says the change raises the concurrency threshold "though this does not fully eliminate the vulnerability under sustained traffic." The empty-path outlet advisory gives equivalent guidance ("though it does not eliminate the issue").
Overview
The Angular project has published four security advisories for its server-side rendering (SSR) code in roughly a week. Three are denial-of-service flaws in @angular/router, each scored 8.2 under CVSS v4, and one is a moderate open redirect in @angular/platform-server. The most recent, published October 1, is fixed in Angular 22.2.1 and 21.2.25.
What We Know
Numeric matrix parameters (September 23)
The first advisory, titled “Denial of Service via Numeric URL Matrix Parameters in Server-Side Rendering (SSR)”, is rated High with a CVSS v4 score of 8.2 and carries the identifier CVE-2026-101896. It was published September 23. It describes an “asymmetric memory amplification factor of approximately ~350x”: an 11-byte segment such as /a;990;2522 consumes roughly 20-25 KB of V8 heap. It affects @angular/router from 22.0.0 before 22.2.0, from 21.0.0 before 21.2.24, and from 20.0.0 before 20.3.32, and is patched in 22.2.0, 21.2.24 and 20.3.32. The advisory lists reverse-proxy rejection of URLs containing semicolons as a workaround and says client-side SPAs without SSR remain unaffected.
Empty-path outlets (September 30)
The second advisory, “Denial of Service via Unmatched Empty-Path Outlet Route Matching in Server-Side Rendering (SSR)”, is also High at 8.2 and lists no CVE. According to the advisory, the router fails to validate whether auxiliary outlet segments match configured routes, which lets unconfigured empty-path outlets cause the router to instantiate duplicate ActivatedRouteSnapshot trees and run guards and resolvers repeatedly. A single crafted request can lead to heap exhaustion and process termination. The advisory says client-side SPAs and prerendering (SSG) are unaffected. Affected ranges are 22.0.0 before 22.2.1, 21.0.0 before 21.2.25, and 20.0.0 before 20.3.33; those three versions are the patched releases.
Protocol-relative open redirect (September 30)
The third advisory covers @angular/platform-server and is rated Moderate with a CVSS v4 score of 5.1 and no CVE. Per the advisory, URLs containing dot-segment sequences such as /.//evil.test bypass the initial protocol-relative URL check; after WHATWG URL normalization the pathname begins with //, and it can be emitted into HTTP Location headers, producing an off-origin redirect. The affected and patched ranges match the second advisory. Suggested mitigations include configuring proxies to reject requests containing /.// or /.;/.
RouterLink query parameter retention (October 1)
The fourth advisory, “Denial of Service via RouterLink Query Parameter Retention in Server-Side Rendering (SSR)”, is High at 8.2 with no CVE. It says that starting in v21.2.0, refactored RouterLink internals introduced computed signals that cached URL tree instances, “permanently pinning the UrlTree and its associated query parameter dictionary in the heap until the SSR response completed.” It affects 22.0.0 before 22.2.1 and 21.2.0 before 21.2.25. The advisory lists removing defaultQueryParamsHandling: 'merge' as one workaround and says client-side SPAs without SSR remain unaffected.
The patch releases
The Angular 22.2.1 release notes list a platform-server fix to “reject protocol-relative paths in resolveUrl” and router fixes including “reject duplicate outlets in production builds”, “require outlets to match a route before processing child segments” and “do not retain UrlTree instances in RouterLink”. The 20.3.33 release notes carry the platform-server fix and the two outlet-related router fixes.
What We Don’t Know
- Three of the four advisories list no CVE identifier; only the September 23 advisory does.
- The advisories do not say whether any of the flaws have been exploited in the wild.
- Versions up to 19.2.25 are marked end of support in the first three advisories and will not be patched, so applications on that line have no upstream fix.
Practical Scope
Per the September 23 advisory, exposure depends on running Angular SSR on Node.js, with user-controlled URLs parsed by @angular/router and reverse proxies that forward semicolons without filtering. The empty-path outlet advisory lists raising Node.js’s --max-old-space-size as a mitigation, while the September 23 advisory describes it as a temporary measure.