HIGH
Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
Published Sep 30, 2026
8.2
HIGHCVSS 4.0
Description
Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
Affected products
No data.
No data.
No data.
No Red Hat product state for this CVE.
@angular/router
npm
Introduced 22.0.0 Fixed 22.2.0@angular/router
npm
Introduced 21.0.0 Fixed 21.2.24@angular/router
npm
Introduced 20.0.0 Fixed 20.3.32@angular/router
npm
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @angular/router | 22.0.0 | 22.2.0 |
| npm | @angular/router | 21.0.0 | 21.2.24 |
| npm | @angular/router | 20.0.0 | 20.3.32 |
| npm | @angular/router | 0 | not fixed |
Remediation
No remediation recorded yet.
Metrics
8.2 HIGH GHSA
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Attack Vector Network
Attack Complexity Low
Attack Requirements Present
Privileges Required None
User Interaction None
Vulnerable System Confidentiality None
Vulnerable System Integrity None
Vulnerable System Availability High
Subsequent System Confidentiality None
Subsequent System Integrity None
Subsequent System Availability None
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
No EPSS score for this CVE.
References (7)
- https://github.com/advisories/GHSA-ff3f-86qr-9cv3 Advisory
- https://github.com/angular/angular/commit/03872a80bcf1c89b2b04cdd3f444b2ee954da583
- https://github.com/angular/angular/commit/5af61216eab8bf4a6697a1d79bda3d857c06f89d
- https://github.com/angular/angular/commit/ddfe21072ba32ca4cd9d7d3c6b7df66af81d58c4
- https://github.com/angular/angular/issues/70716
- https://github.com/angular/angular/pull/70717
- https://github.com/angular/angular/security/advisories/GHSA-ff3f-86qr-9cv3
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status n/a
Assigner n/a
Published Sep 30, 2026
Updated n/a
Reserved n/a
Link CVE-2026-101896
CISA Vulnrichment
GHSA-FF3F-86QR-9CV3 Updated n/a