Excessive Iteration in Angular - CVE-2026-50171
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to excessive iteration in the formatNumber function when processing a crafted digitsInfo parameter. A remote attacker can supply a digitsInfo value with excessively large fraction digit values to cause a denial of service.
Affected formatting utilities include DecimalPipe, PercentPipe, and CurrencyPipe.