CVE-2026-101895

HIGHCVSS · not yet scored
—
EchelonGraph verdictMonitorLow exploitation likelihood right now — keep watching.
  • No CVSS published and no exploitation signals yet
CISA-KEV: Not listedEPSS PROB: —CVSS v2: —Exploit: None knownExposed services: Not assessed

No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.

Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE

A Denial of Service (DoS) vulnerability exists in @angular/platform-server's DOM emulation parser (domino). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF (such as ), the HTML parser enters an infinite synchronous loop, pegging CPU utilization at 100% and completely freezing the Node.js server process.

Technical Description

In Angular Server-Side Rendering (SSR), @angular/platform-server uses domino to parse and sanitize HTML bound through template bindings (such as [innerHTML]) or manipulated via DOM APIs.

In Domino's HTML parser (lib/HTMLParser.js), tokenizer states that specify fixed lookahead—such as after_doctype_name_state (lookahead = 6)—rely on the state handler function to explicitly advance the character index pointer (nextchar). While branches for whitespace, >, and keyword matching advance nextchar, the EOF branch (case -1: // EOF) emitted doctype and EOF tokens without advancing nextchar or transitioning out of the state:

case -1: // EOF
  forcequirks();
  emitDoctype();
  emitEOF();
  break;

Because nextchar remained unchanged pointing to the EOF marker character (\uFFFF), the scanner loop (while (nextchar < numchars)) repeatedly re-invoked after_doctype_name_state with codepoint = EOF indefinitely. In Node.js's single-threaded runtime, this synchronous loop starves the event loop entirely.

Impact & Reachability

* Reachability: The vulnerability is reachable in any Angular SSR application where untrusted user input is bound to [innerHTML], interpolated into markup, or sanitized on the server. * Impact: Successful exploitation allows an unauthenticated remote attacker to cause an immediate Denial of Service (DoS) by sending a payload containing an incomplete DOCTYPE (e.g., ). The Node.js SSR process locks up at 100% CPU and ceases responding to all concurrent and subsequent HTTP requests.

Proof of Concept:

import { Component } from '@angular/core';

@Component({ selector: 'app-root', standalone: true, template: `, }) export class AppComponent { // Attacker-controlled input containing an incomplete DOCTYPE ending with whitespace payload = '<!DOCTYPE html '; }

Workarounds

* Avoid binding untrusted user input directly to [innerHTML] in server-rendered templates; use standard text interpolation ({{ userInput }}) or [textContent] when raw HTML rendering is not required. * Validate or sanitize user input before passing it to [innerHTML] on the server by stripping or rejecting strings matching /^
CVSS v3
—
EchelonGraph score
Not yet assessedNo source has published severity data for this CVE yet — no CVSS score from NVD or a CNA, no GitHub advisory, and it is not in CISA KEV. This is not a rating of zero; we cannot assess it yet.
EG Score
—
EG Risk
—
EPSS PROB
—
EPSS %ILE
—
KEV
Not listed

Published

September 28, 2026

Last Modified

September 28, 2026

Vendor Advisories for CVE-2026-101895(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Affected Packages

(1 across 1 ecosystem)
npm(1)
PackageVulnerable rangeFix by version rangeDependents
@angular/platform-server—
  • 22.0.0 up to 22.1.6: fixed in 22.1.6
  • 21.0.0 up to 21.2.23: fixed in 21.2.23
  • 20.0.0 up to 20.3.31: fixed in 20.3.31
  • every version through 19.2.25: no fix on record
—

Data Freshness Timeline

(refreshed 1× in last 7d / 1× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-09-28 22:10 UTCEG score recompute

Frequently asked(3)

What is CVE-2026-101895?
CVE-2026-101895 is a high vulnerability published on September 28, 2026. Angular SSR: Denial of Service (DoS) via Infinite Loop on Malformed DOCTYPE A Denial of Service (DoS) vulnerability exists in @angular/platform-server's DOM emulation parser (domino). When processing untrusted user input containing an incomplete DOCTYPE declaration ending with whitespace before EOF…
When was CVE-2026-101895 disclosed?
CVE-2026-101895 was first published on September 28, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
How do I remediate CVE-2026-101895?
No fix for CVE-2026-101895 is confirmed yet. Until one is published, restrict network exposure of the affected system or apply the vendor's mitigation — for example, keep it off the internet or limit it to trusted networks — and watch the vendor's advisory for the fix. The vendor advisories EchelonGraph has for CVE-2026-101895 are linked in the Vendor Advisories panel on this page.

Dependency Blast Radius

See which npm, PyPI, Go, and Maven packages are affected by CVE-2026-101895

Explore →

Is Your Infrastructure Affected by CVE-2026-101895?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.