Answer in brief
CVE-2026-101895 records a High severity vulnerability in Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE. The current sources do not mark it as known exploited. The current feed maps @angular/platform-server (npm), @angular/platform-server (npm), @angular/platform-server (npm), @angular/platform-server (npm) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps @angular/platform-server (npm), @angular/platform-server (npm), @angular/platform-server (npm), @angular/platform-server (npm) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| @angular/platform-servernpm | >=22.0.0,<22.1.6 | 22.1.6 |
| @angular/platform-servernpm | >=21.0.0,<21.2.23 | 21.2.23 |
| @angular/platform-servernpm | >=20.0.0,<20.3.31 | 20.3.31 |
| @angular/platform-servernpm | <=19.2.25 | Not reported |
| @angular/platform-servernpm | >=22.0.0 <22.1.6 | 22.1.6 |
| @angular/platform-servernpm | >=21.0.0 <21.2.23 | 21.2.23 |
| @angular/platform-servernpm | >=20.0.0 <20.3.31 | 20.3.31 |
| @angular/platform-servernpm | >=0 | Not reported |
Published upstream
Sep 28, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Sep 28, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Sep 28, 2026
A Denial of Service (DoS) vulnerability exists in `@angular/platform-server`'s DOM emulation parser (`domino`). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF (such as `<!DOCTYPE html `), the HTML parser enters an infinite synchronous loop, pegging CPU utilization at 100% and completely freezing the Node.js server process. ### Technical Description In Angular Server-Side Rendering (SSR), `@angular/platform-server` uses `domino` to parse and sanitize HTML bound through template bindings (such as `[innerHTML]`) or manipulated via DOM APIs. In Domino's HTML parser (`lib/HTMLParser.js`), tokenizer states that specify fixed lookahead—such as `after_doctype_name_state` (`lookahead = 6`)—rely on the state handler function to explicitly advance the character index pointer (`nextchar`). While branches for whitespace, `>`, and keyword matching advance `nextchar`, the EOF branch (`case -1: // EOF`) emitted doctype and EOF tokens without advancing `nextchar` or transitioning out of the state: ```javascript case -1: // EOF forcequirks(); emitDoctype(); emitEOF(); break; ``` Because `nextchar` remained unchanged pointing to the EOF marker character (`\uFFFF`), the scanner loop (`while (nextchar < numchars)`) repeatedly re-invoked `after_doctype_name_state` with `codepoint = EOF` indefinitely. In Node.js's single-threaded runtime, this synchronous loop starves the event loop entirely. ### Impact & Reachability * **Reachability**: The vulnerability is reachable in any Angular SSR application where untrusted user input is bound to `[innerHTML]`, interpolated into markup, or sanitized on the server. * **Impact**: Successful exploitation allows an unauthenticated remote attacker to cause an immediate Denial of Service (DoS) by sending a payload containing an incomplete DOCTYPE (e.g., `<!DOCTYPE html `). The Node.js SSR process locks up at 100% CPU and ceases responding to all concurrent and subsequent HTTP requests. **Proof of Concept:** ```ts import { Component } from '@angular/core'; @Component({ selector: 'app-root', standalone: true, template: `<div [innerHTML]="payload"></div>`, }) export class AppComponent { // Attacker-controlled input containing an incomplete DOCTYPE ending with whitespace payload = '<!DOCTYPE html '; } ``` ### Workarounds * Avoid binding untrusted user input directly to `[innerHTML]` in server-rendered templates; use standard text interpolation (`{{ userInput }}`) or `[textContent]` when raw HTML rendering is not required. * Validate or sanitize user input before passing it to `[innerHTML]` on the server by stripping or rejecting strings matching `/^<!DOCTYPE/i`.
Quoted source text, attributed separately from HOL analysis.