
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-101895 is a Denial of Service (DoS) vulnerability in @angular/platform-server's DOM emulation parser (domino), caused by an infinite synchronous loop when processing malformed DOCTYPE declarations. When untrusted input containing an incomplete DOCTYPE ending with whitespace before EOF (e.g., <!DOCTYPE html) is parsed, the Node.js server process pegs CPU at 100% and becomes completely unresponsive. Affected versions include @angular/platform-server >= 22.0.0 < 22.1.6, >= 21.0.0 < 21.2.23, >= 20.0.0 < 20.3.31, and <= 19.2.25 (end-of-life, will not be patched). It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Angular Advisory).
The root cause is classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop). In Domino's HTML parser (lib/HTMLParser.js), tokenizer states with fixed lookahead — such as after_doctype_name_state (lookahead = 6) — rely on the state handler to advance the character index pointer (nextchar). The EOF branch (case -1: // EOF) calls forcequirks(), emitDoctype(), and emitEOF() but never advances nextchar or transitions out of the state, leaving it pointing to the EOF marker character (\uFFFF). The scanner loop (while (nextchar < numchars)) then re-invokes the same state handler indefinitely, starving Node.js's single-threaded event loop. The vulnerability is reachable in any Angular SSR application where untrusted user input is bound to [innerHTML], interpolated into markup, or sanitized server-side (GitHub Advisory, Angular Advisory).
Successful exploitation allows an unauthenticated remote attacker to immediately freeze the Node.js server process by sending a single crafted HTTP request containing a malformed DOCTYPE payload. The server's CPU is consumed at 100% in a synchronous infinite loop, rendering the application completely unresponsive to all subsequent requests. There is no confidentiality or integrity impact, but the availability impact is total for the affected server process; in containerized or single-instance deployments, this effectively takes the entire application offline (GitHub Advisory, Angular Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The vulnerability requires no authentication, no special privileges, and no user interaction — an attacker only needs to send a single HTTP request with a crafted payload to a reachable Angular SSR endpoint. The attack vector is network-accessible and the attack complexity is low, making it trivially exploitable once an attacker identifies a vulnerable endpoint. No EPSS score or CISA KEV catalog entry is currently associated with this CVE (GitHub Advisory, Angular Advisory).
ng-server-context attributes in HTML responses, or known Angular SSR framework fingerprints).[innerHTML] bindings, DOM manipulation, or server-side sanitization in the Angular SSR context.<!DOCTYPE html (no closing >).<!DOCTYPE strings lacking a closing >, particularly ending with whitespace; single requests from an IP followed by complete server unresponsiveness.Upgrade @angular/platform-server to one of the patched versions: 22.1.6, 21.2.23, or 20.3.31. Angular v19 and below are end-of-life and will not receive patches — applications on those versions should be upgraded to a supported major version. As interim mitigations, implement server-side input validation to reject or normalize malformed DOCTYPE declarations before they reach the HTML parser, and deploy request timeout mechanisms and rate limiting to limit the impact of DoS attempts. Consider placing Angular SSR instances behind a reverse proxy or WAF that can enforce request body size limits and detect anomalous payloads (GitHub Advisory, Angular Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."