GHSA-f67j-2jqw-jpq7

Suggest an improvement
Source
https://github.com/advisories/GHSA-f67j-2jqw-jpq7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-f67j-2jqw-jpq7/GHSA-f67j-2jqw-jpq7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-f67j-2jqw-jpq7
Aliases
  • CVE-2026-101895
Published
2026-09-28T21:31:21Z
Modified
2026-09-28T21:45:03Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
Details

A Denial of Service (DoS) vulnerability exists in @angular/platform-server's DOM emulation parser (domino). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF (such as <!DOCTYPE html ), the HTML parser enters an infinite synchronous loop, pegging CPU utilization at 100% and completely freezing the Node.js server process.

Technical Description

In Angular Server-Side Rendering (SSR), @angular/platform-server uses domino to parse and sanitize HTML bound through template bindings (such as [innerHTML]) or manipulated via DOM APIs.

In Domino's HTML parser (lib/HTMLParser.js), tokenizer states that specify fixed lookahead—such as after_doctype_name_state (lookahead = 6)—rely on the state handler function to explicitly advance the character index pointer (nextchar). While branches for whitespace, >, and keyword matching advance nextchar, the EOF branch (case -1: // EOF) emitted doctype and EOF tokens without advancing nextchar or transitioning out of the state:

case -1: // EOF
  forcequirks();
  emitDoctype();
  emitEOF();
  break;

Because nextchar remained unchanged pointing to the EOF marker character (\uFFFF), the scanner loop (while (nextchar < numchars)) repeatedly re-invoked after_doctype_name_state with codepoint = EOF indefinitely. In Node.js's single-threaded runtime, this synchronous loop starves the event loop entirely.

Impact & Reachability

  • Reachability: The vulnerability is reachable in any Angular SSR application where untrusted user input is bound to [innerHTML], interpolated into markup, or sanitized on the server.
  • Impact: Successful exploitation allows an unauthenticated remote attacker to cause an immediate Denial of Service (DoS) by sending a payload containing an incomplete DOCTYPE (e.g., <!DOCTYPE html ). The Node.js SSR process locks up at 100% CPU and ceases responding to all concurrent and subsequent HTTP requests.

Proof of Concept:

import { Component } from '@angular/core';

@Component({
  selector: 'app-root',
  standalone: true,
  template: `<div [innerHTML]="payload"></div>`,
})
export class AppComponent {
  // Attacker-controlled input containing an incomplete DOCTYPE ending with whitespace
  payload = '<!DOCTYPE html ';
}

Workarounds

  • Avoid binding untrusted user input directly to [innerHTML] in server-rendered templates; use standard text interpolation ({{ userInput }}) or [textContent] when raw HTML rendering is not required.
  • Validate or sanitize user input before passing it to [innerHTML] on the server by stripping or rejecting strings matching /^<!DOCTYPE/i.
Database specific
{
    "cwe_ids":  [
        "CWE-400",
        "CWE-835"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-28T21:31:21Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / @angular/platform-server

Package

Name
@angular/platform-server
View open source insights on deps.dev
Purl
pkg:npm/%40angular/platform-server

Affected ranges

Type
SEMVER
Events
Introduced
22.0.0
Fixed
22.1.6

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-f67j-2jqw-jpq7/GHSA-f67j-2jqw-jpq7.json"

npm / @angular/platform-server

Package

Name
@angular/platform-server
View open source insights on deps.dev
Purl
pkg:npm/%40angular/platform-server

Affected ranges

Type
SEMVER
Events
Introduced
21.0.0
Fixed
21.2.23

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-f67j-2jqw-jpq7/GHSA-f67j-2jqw-jpq7.json"

npm / @angular/platform-server

Package

Name
@angular/platform-server
View open source insights on deps.dev
Purl
pkg:npm/%40angular/platform-server

Affected ranges

Type
SEMVER
Events
Introduced
20.0.0
Fixed
20.3.31

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-f67j-2jqw-jpq7/GHSA-f67j-2jqw-jpq7.json"

npm / @angular/platform-server

Package

Name
@angular/platform-server
View open source insights on deps.dev
Purl
pkg:npm/%40angular/platform-server

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
19.2.25

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-f67j-2jqw-jpq7/GHSA-f67j-2jqw-jpq7.json"