Asymmetric Resource Consumption (Amplification) in Angular - #VU153183
Published: October 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of auxiliary outlet segments in @angular/router route recognition when processing crafted request URLs containing arbitrary empty-path outlet segments. A remote attacker can send a crafted request to cause a denial of service.
Only on-demand server-side rendering applications running on Node.js/V8 with susceptible route configurations are affected.