Junglewise Threat Intelligence

CVE-2026-50171: Google Angular Denial of Service in @angular/common number formatting

CVE-2026-50171 · Severity: high · CVSS 3.1 · Published 2026-06-22

Vendors: Google.

Executive brief

Angular is a popular development framework used to build web and mobile applications. A flaw in how it handles number formatting allows an attacker to crash a web server or freeze a user's browser by providing specially crafted, excessively large formatting instructions. This can lead to a total service outage for applications using server-side rendering or a broken user experience for individual visitors.

Technical details

A Denial of Service (DoS) vulnerability exists in the @angular/common package of Angular within the formatNumber function and associated pipes (DecimalPipe, PercentPipe, CurrencyPipe). The root cause is a failure to validate the upper bounds of the digitsInfo parameter; when excessively large fraction digit values are provided, the internal roundNumber function enters an unbounded loop while attempting to pad a digits array. In Server-Side Rendering (SSR) environments, this leads to a Node.js heap out-of-memory (OOM) crash. In Client-Side Rendering (CSR) environments, it blocks the main thread, causing the browser tab to become unresponsive. Exploitation requires that the digitsInfo parameter be controllable by untrusted user input.

Affected products

  • Google Angular < 19.2.23, >= 20.0.0-next.0 < 20.3.22, >= 21.0.0-next.0 < 21.2.15, >= 22.0.0-next.0 < 22.0.0-rc.2

Timeline

  • 2026-05-28: advisory: GitHub advisory published by Angular maintainers
  • 2026-06-22: disclosed: NVD publication date
  • 2026-06-22: patched: Fixes released in versions 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23

References