Vulnerability GHSA-f67j-2jqw-jpq7

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
1 hour ago
September 28, 2026 at 09:31 PM UTC
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
0.0.0-0 - 19.2.25 and 20.0.0 - 20.3.30 and 21.0.0 - 21.2.22 and 22.0.0 - 22.1.5
0.0.0-0 - 19.2.25 and 20.0.0 - 20.3.30 and 21.0.0 - 21.2.22 and 22.0.0 - 22.1.5

Summary

Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE

Details

A Denial of Service (DoS) vulnerability exists in @angular/platform-server's DOM emulation parser (domino). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF (such as <!DOCTYPE html ), the HTML parser enters an infinite synchronous loop, pegging CPU utilization at 100% and completely freezing the Node.js server process.

Technical Description

In Angular Server-Side Rendering (SSR), @angular/platform-server uses domino to parse and sanitize HTML bound through template bindings (such as [innerHTML]) or manipulated via DOM APIs.

In Domino's HTML parser (lib/HTMLParser.js), tokenizer states that specify fixed lookahead—such as after_doctype_name_state (lookahead = 6)—rely on the state handler function to explicitly advance the character index pointer (nextchar). While branches for whitespace, >, and keyword matching advance nextchar, the EOF branch (case -1: // EOF) emitted doctype and EOF tokens without advancing nextchar or transitioning out of the state:

case -1: // EOF
  forcequirks();
  emitDoctype();
  emitEOF();
  break;

Because nextchar remained unchanged pointing to the EOF marker character (\uFFFF), the scanner loop (while (nextchar < numchars)) repeatedly re-invoked after_doctype_name_state with codepoint = EOF indefinitely. In Node.js's single-threaded runtime, this synchronous loop starves the event loop entirely.

Impact & Reachability

  • Reachability: The vulnerability is reachable in any Angular SSR application where untrusted user input is bound to [innerHTML], interpolated into markup, or sanitized on the server.
  • Impact: Successful exploitation allows an unauthenticated remote attacker to cause an immediate Denial of Service (DoS) by sending a payload containing an incomplete DOCTYPE (e.g., <!DOCTYPE html ). The Node.js SSR process locks up at 100% CPU and ceases responding to all concurrent and subsequent HTTP requests.

Proof of Concept:

import { Component } from '@angular/core';

@Component({
  selector: 'app-root',
  standalone: true,
  template: `<div [innerHTML]="payload"></div>`,
})
export class AppComponent {
  // Attacker-controlled input containing an incomplete DOCTYPE ending with whitespace
  payload = '<!DOCTYPE html ';
}

Workarounds

  • Avoid binding untrusted user input directly to [innerHTML] in server-rendered templates; use standard text interpolation ({{ userInput }}) or [textContent] when raw HTML rendering is not required.
  • Validate or sanitize user input before passing it to [innerHTML] on the server by stripping or rejecting strings matching /^<!DOCTYPE/i.

Related Vulnerabilities

Other vulnerabilities affecting the same packages

View all vulnerabilities for these packages

Impacted packages

Timeline

Published
1 hour ago
September 28, 2026 at 09:31 PM UTC
Fixed (22.1.6)
19 days ago
September 09, 2026 at 08:13 PM UTC
Fixed (21.2.23)
Unknown
Unknown
Fixed (20.3.31)
Unknown
Unknown
Last Modified
1 hour ago
September 28, 2026 at 09:45 PM UTC