HIGH
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
Published Sep 28, 2026
8.7
HIGHCVSS 4.0
Description
Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE
Affected products
No data.
No data.
No data.
No Red Hat product state for this CVE.
@angular/platform-server
npm
Introduced 20.0.0 Fixed 20.3.31@angular/platform-server
npm
Introduced 0 Fixed not fixed@angular/platform-server
npm
Introduced 22.0.0 Fixed 22.1.6@angular/platform-server
npm
Introduced 21.0.0 Fixed 21.2.23
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @angular/platform-server | 20.0.0 | 20.3.31 |
| npm | @angular/platform-server | 0 | not fixed |
| npm | @angular/platform-server | 22.0.0 | 22.1.6 |
| npm | @angular/platform-server | 21.0.0 | 21.2.23 |
Remediation
No remediation recorded yet.
Metrics
8.7 HIGH GHSA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Attack Vector Network
Attack Complexity Low
Attack Requirements None
Privileges Required None
User Interaction None
Vulnerable System Confidentiality None
Vulnerable System Integrity None
Vulnerable System Availability High
Subsequent System Confidentiality None
Subsequent System Integrity None
Subsequent System Availability None
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
Weaknesses (2)
References (2)
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Sep 28, 2026
Updated n/a
Reserved n/a
Link CVE-2026-101895
CISA Vulnrichment
GHSA-F67J-2JQW-JPQ7 Updated n/a