Answer in brief
CVE-2026-54268 records a High severity (CVSS 8.2) vulnerability in @angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate). The current sources do not mark it as known exploited. The current feed maps @angular/common (npm), @angular/common (npm), @angular/common (npm), @angular/common (npm) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 8.2. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps @angular/common (npm), @angular/common (npm), @angular/common (npm), @angular/common (npm) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| @angular/commonnpm | >=22.0.0-next.0,<22.0.1 | 22.0.1 |
| @angular/commonnpm | >=21.0.0-next.0,<21.2.17 | 21.2.17 |
| @angular/commonnpm | >=20.0.0-next.0,<20.3.25 | 20.3.25 |
| @angular/commonnpm | <=19.2.25 | Not reported |
| @angular/commonnpm | >=22.0.0-next.0<22.0.1 | Not reported |
| @angular/commonnpm | >=21.0.0-next.0<21.2.17 | Not reported |
| @angular/commonnpm | >=20.0.0-next.0<20.3.25 | Not reported |
| @angular/commonnpm | >=22.0.0-next.0 <22.0.1 | 22.0.1 |
| @angular/commonnpm | >=21.0.0-next.0 <21.2.17 | 21.2.17 |
| @angular/commonnpm | >=20.0.0-next.0 <20.3.25 | 20.3.25 |
| @angular/commonnpm | >=0 | Not reported |
Published upstream
Jun 10, 2026
Evidence: source:ghsa:source_dates:source-dates:recordSource modified
Sep 10, 2026
Evidence: source:ghsa:source_dates:source-dates:recordFirst seen by HOL
Jun 19, 2026
A Denial of Service (DoS) vulnerability exists in the `@angular/common` package of the Angular framework. The `formatDate` function, which is also utilized by the standard Angular `DatePipe`, does not properly limit or validate the length of the `format` parameter. When parsing a maliciously crafted, excessively long date format string (e.g., a repeating pattern or very large string), the internal parser splits the string iteratively using a regular expression loop. This results in uncontrolled resource consumption (high CPU utilization and excessive memory allocations), leading to a Denial of Service (DoS). ### Impact #### 1. Server-Side Rendering (SSR) In Angular applications that leverage Server-Side Rendering, an attacker can supply a malicious payload with an excessively long date format string. Processing this on the server causes high CPU usage and triggers a `JavaScript heap out of memory` crash, rendering the application unavailable to all users. #### 2. Client-Side Rendering (CSR) In standard client-side applications, executing the vulnerable function with an excessively long format string blocks the browser's main thread, causing the browser tab to freeze and become completely unresponsive. ### Patched Versions * 22.0.1 * 21.2.17 * 20.3.25 ### Attack Preconditions For this vulnerability to be exploitable, both of the following conditions must be met: 1. **Vulnerable Component Usage:** The application must format dates using the `formatDate` utility or the `DatePipe`. 2. **Attacker-Controlled Parameter:** The date format string passed to these utilities must be customizable or directly controlled by untrusted user input (e.g., parsed from query parameters, user preferences, or API responses). *If the date format is hardcoded (e.g., `'mediumDate'`, `'shortTime'`, or static strings) or properly validated to be within a reasonable length limit, the application is not vulnerable.* ### References - https://github.com/angular/angular/pull/69197
Quoted source text, attributed separately from HOL analysis.