Vulnerability DatabaseCVE-2026-101895

CVE-2026-101895: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-101895 is a Denial of Service (DoS) vulnerability in @angular/platform-server's DOM emulation parser (domino), caused by an infinite synchronous loop when processing malformed DOCTYPE declarations. When untrusted input containing an incomplete DOCTYPE ending with whitespace before EOF (e.g., <!DOCTYPE html) is parsed, the Node.js server process pegs CPU at 100% and becomes completely unresponsive. Affected versions include @angular/platform-server >= 22.0.0 < 22.1.6, >= 21.0.0 < 21.2.23, >= 20.0.0 < 20.3.31, and <= 19.2.25 (end-of-life, will not be patched). It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Angular Advisory).

Technical details

The root cause is classified as CWE-400 (Uncontrolled Resource Consumption) and CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop). In Domino's HTML parser (lib/HTMLParser.js), tokenizer states with fixed lookahead — such as after_doctype_name_state (lookahead = 6) — rely on the state handler to advance the character index pointer (nextchar). The EOF branch (case -1: // EOF) calls forcequirks(), emitDoctype(), and emitEOF() but never advances nextchar or transitions out of the state, leaving it pointing to the EOF marker character (\uFFFF). The scanner loop (while (nextchar < numchars)) then re-invokes the same state handler indefinitely, starving Node.js's single-threaded event loop. The vulnerability is reachable in any Angular SSR application where untrusted user input is bound to [innerHTML], interpolated into markup, or sanitized server-side (GitHub Advisory, Angular Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to immediately freeze the Node.js server process by sending a single crafted HTTP request containing a malformed DOCTYPE payload. The server's CPU is consumed at 100% in a synchronous infinite loop, rendering the application completely unresponsive to all subsequent requests. There is no confidentiality or integrity impact, but the availability impact is total for the affected server process; in containerized or single-instance deployments, this effectively takes the entire application offline (GitHub Advisory, Angular Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at the time of disclosure. The vulnerability requires no authentication, no special privileges, and no user interaction — an attacker only needs to send a single HTTP request with a crafted payload to a reachable Angular SSR endpoint. The attack vector is network-accessible and the attack complexity is low, making it trivially exploitable once an attacker identifies a vulnerable endpoint. No EPSS score or CISA KEV catalog entry is currently associated with this CVE (GitHub Advisory, Angular Advisory).

Exploitation steps

  1. Reconnaissance: Identify Angular SSR applications exposed to the internet by looking for server-rendered Angular pages (e.g., presence of ng-server-context attributes in HTML responses, or known Angular SSR framework fingerprints).
  2. Identify injectable endpoints: Locate application routes or API endpoints that accept user-controlled HTML input and pass it through [innerHTML] bindings, DOM manipulation, or server-side sanitization in the Angular SSR context.
  3. Craft the malicious payload: Construct an HTTP request body or query parameter containing an incomplete DOCTYPE declaration ending with whitespace before EOF, such as <!DOCTYPE html (no closing >).
  4. Send the request: Submit the crafted payload to the vulnerable endpoint via a standard HTTP POST or GET request — no authentication or special headers required.
  5. Observe DoS: The Node.js server process enters an infinite synchronous loop processing the malformed DOCTYPE, consuming 100% CPU and becoming unresponsive to all further requests, effectively taking the application offline (GitHub Advisory, Angular Advisory).

Indicators of compromise

  • Network: Incoming HTTP requests to Angular SSR endpoints containing payloads with <!DOCTYPE strings lacking a closing >, particularly ending with whitespace; single requests from an IP followed by complete server unresponsiveness.
  • Process: Node.js server process sustaining 100% CPU utilization on a single core with no corresponding increase in throughput or active connections; process becomes unresponsive to health checks.
  • Logs: Application or web server access logs showing a request to an HTML-input-accepting endpoint immediately before the server stops responding; absence of subsequent log entries after the triggering request due to event loop starvation.
  • Infrastructure: Automated health checks or load balancer probes reporting the Node.js instance as unhealthy or timing out shortly after a specific inbound request (GitHub Advisory).

Mitigation and workarounds

Upgrade @angular/platform-server to one of the patched versions: 22.1.6, 21.2.23, or 20.3.31. Angular v19 and below are end-of-life and will not receive patches — applications on those versions should be upgraded to a supported major version. As interim mitigations, implement server-side input validation to reject or normalize malformed DOCTYPE declarations before they reach the HTML parser, and deploy request timeout mechanisms and rate limiting to limit the impact of DoS attempts. Consider placing Angular SSR instances behind a reverse proxy or WAF that can enforce request body size limits and detect anomalous payloads (GitHub Advisory, Angular Advisory).

Additional resources


Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-101895HIGH8.7
  • JavaScript logoJavaScript
  • @angular/platform-server
NoYesSep 28, 2026
CVE-2026-55157HIGH8.4
  • JavaScript logoJavaScript
  • @ooples/token-optimizer-mcp
NoYesSep 28, 2026
CVE-2026-101914MEDIUM6.5
  • JavaScript logoJavaScript
  • @grpc/grpc-js-xds
NoYesSep 28, 2026
GHSA-6vj9-mwq6-2f5vMEDIUM5.9
  • JavaScript logoJavaScript
  • nodemailer
NoYesSep 28, 2026
CVE-2026-55156MEDIUM5.3
  • JavaScript logoJavaScript
  • @ooples/token-optimizer-mcp
NoYesSep 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management