Executive brief
Angular is a popular development framework used to build web and mobile applications. A flaw in how it handles number formatting allows an attacker to crash a web server or freeze a user's browser by providing specially crafted, excessively large formatting instructions. This can lead to a total service outage for applications using server-side rendering or a broken user experience for individual visitors.
Technical details
A Denial of Service (DoS) vulnerability exists in the @angular/common package of Angular within the formatNumber function and associated pipes (DecimalPipe, PercentPipe, CurrencyPipe). The root cause is a failure to validate the upper bounds of the digitsInfo parameter; when excessively large fraction digit values are provided, the internal roundNumber function enters an unbounded loop while attempting to pad a digits array. In Server-Side Rendering (SSR) environments, this leads to a Node.js heap out-of-memory (OOM) crash. In Client-Side Rendering (CSR) environments, it blocks the main thread, causing the browser tab to become unresponsive. Exploitation requires that the digitsInfo parameter be controllable by untrusted user input.
Affected products
- Google Angular < 19.2.23, >= 20.0.0-next.0 < 20.3.22, >= 21.0.0-next.0 < 21.2.15, >= 22.0.0-next.0 < 22.0.0-rc.2
Timeline
- 2026-05-28: advisory: GitHub advisory published by Angular maintainers
- 2026-06-22: disclosed: NVD publication date
- 2026-06-22: patched: Fixes released in versions 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23