EXECUTIVE SUMMARY:
Angular has addressed two high-severity vulnerabilities in @angular/platform-server affecting Angular Server-Side Rendering (SSR). One can cause a denial-of-service when an incomplete DOCTYPE declaration containing trailing whitespace triggers an infinite loop in the Domino HTML parser, consuming 100% CPU and freezing the Node.js SSR process. The other is an XSS flaw in SSR HTML serialization where processing instruction nodes inside fallback raw-content elements can contain unescaped closing tags, allowing attacker-controlled content to escape the container and execute JavaScript in a victim's browser. Both vulnerabilities affect multiple Angular release branches and have been addressed in newer versions.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Angular has addressed two high-severity vulnerabilities in @angular/platform-server affecting Angular Server-Side Rendering (SSR). One can cause a denial-of-service when an incomplete DOCTYPE declaration containing trailing whitespace triggers an infinite loop in the Domino HTML parser, consuming 100% CPU and freezing the Node.js SSR process. The other is an XSS flaw in SSR HTML serialization where processing instruction nodes inside fallback raw-content elements can contain unescaped closing tags, allowing attacker-controlled content to escape the container and execute JavaScript in a victim's browser. Both vulnerabilities affect multiple Angular release branches and have been addressed in newer versions.[emaillocker id="1283"]
CVE-2026-88058 (CVSS 8.6 — High): An XSS vulnerability in @angular/platform-server during SSR allows attacker-controlled processing instruction data within fallback raw-content elements to break out of the container and execute arbitrary JavaScript in a victim's browser.
CVE-2026-101895 (CVSS 8.7 — High): A denial-of-service vulnerability in @angular/platform-server allows an unauthenticated remote attacker to trigger an infinite loop by supplying malformed DOCTYPE input, causing the Node.js SSR process to consume CPU and stop responding to requests.
RECOMMENDATIONS:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-j3r3-mxqp-r2p4
https://github.com/advisories/GHSA-f67j-2jqw-jpq7