A vulnerability in @angular/router, identified as CVE-2026-101896 with a CVSS score of 8.2, allows an attacker to exploit a path traversal issue, potentially leading to unintended memory access and resource exhaustion, resulting in denial-of-service or data tampering. The flaw type is a path traversal issue, which can be exploited via the environment template management API, requiring excessive path depth and allowing an attacker with high capability to achieve their goal. This vulnerability affects versions >= 22.0.0, < 22.2.0, >= 21.0.0, < 21.2.24, >= 20.0.0, < 20.3.32, and <= 19.2.25 of @angular/router, with the highest priority source being the 'Affected packages:' section listing patched versions as 22.2.0, 21.2.24, and 20.3.32. To mitigate this vulnerability, it is recommended to enforce strict path segment limits by rejecting requests with excessive path depth (e.g., more than 20–30 segments), similar to the Nginx example that rejects requests containing matrix parameters. Additionally, increasing Node.js old space by adjusting the '--max-old-space-size' parameter can help increase the concurrency threshold required to exhaust memory, though this does not fully eliminate the vulnerability under sustained traffic.
We recommend you to update @angular/router to versions 22.2.0, 21.2.24, or 20.3.32.[/subscribe_to_unlock_form]
A vulnerability in @angular/router, identified as CVE-2026-101896 with a CVSS score of 8.2, allows an attacker to exploit a path traversal issue, potentially leading to unintended memory access and resource exhaustion, resulting in denial-of-service or data tampering. The flaw type is a path traversal issue, which can be exploited via the environment template management API, requiring excessive path depth and allowing an attacker with high capability to achieve their goal. This vulnerability affects versions >= 22.0.0, < 22.2.0, >= 21.0.0, < 21.2.24, >= 20.0.0, < 20.3.32, and <= 19.2.25 of @angular/router, with the highest priority source being the 'Affected packages:' section listing patched versions as 22.2.0, 21.2.24, and 20.3.32. To mitigate this vulnerability, it is recommended to enforce strict path segment limits by rejecting requests with excessive path depth (e.g., more than 20–30 segments), similar to the Nginx example that rejects requests containing matrix parameters. Additionally, increasing Node.js old space by adjusting the '--max-old-space-size' parameter can help increase the concurrency threshold required to exhaust memory, though this does not fully eliminate the vulnerability under sustained traffic.
We recommend you to update @angular/router to versions 22.2.0, 21.2.24, or 20.3.32.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]