Resource exhaustion in Angular - #VU151872
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in @angular/router when parsing request URLs with numeric matrix parameter names. A remote attacker can send concurrent crafted requests containing repeated numeric matrix parameters to cause a denial of service.
Exploitation requires a Node.js/V8 server-side rendering deployment in which upstream proxies forward semicolon-containing, multi-segment URLs.