Allocation of Resources Without Limits or Throttling in Angular - #VU153182
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the @angular/router RouterLink directive when server-side rendering RouterLink directives with merged or preserved query parameters. A remote attacker can send concurrent HTTP requests containing oversized query strings to exhaust the Node.js worker heap and terminate the SSR worker.
Exploitation requires overlapping server-side renders in the same Node.js worker and an upstream proxy or load balancer that forwards long query strings.