Junglewise Threat Intelligence

CVE-2026-54268: Google Angular Denial of Service in formatDate and DatePipe

CVE-2026-54268 · Severity: high · CVSS 3.1 · Published 2026-06-22

Technologies: Google Angular Common. Vendors: Angular, Google.

Executive brief

The @angular/common library's formatDate function and DatePipe do not validate the length of date format strings, allowing attackers to supply excessively long format parameters that cause memory exhaustion and high CPU usage. In server-side rendering applications, this can crash the JavaScript heap and make the application unavailable to all users; in client-side applications, it can freeze the browser tab. The vulnerability requires the date format string to be user-controlled rather than hardcoded.

Technical details

A Denial of Service vulnerability exists in Angular's formatDate function (and the DatePipe that uses it) due to missing input validation on the format parameter. The internal parser splits the format string iteratively using a regular expression loop without enforcing a length limit, causing uncontrolled resource consumption when processing maliciously crafted excessively long format strings. Attack preconditions require both vulnerable component usage (formatDate or DatePipe) and attacker-controlled format strings passed via query parameters, user preferences, or API responses. Applications with hardcoded or validated format strings are not vulnerable. The patch introduces a maximum length of 256 characters for date format strings, rejecting longer inputs with an INVALID_DATE_FORMAT error. Patches are available in versions 22.0.1, 21.2.17, 20.3.25, and version 19.2.25 is the last affected version.

Affected products

  • Angular @angular/common 22.0.0-next.0 to <22.0.1; 21.0.0-next.0 to <21.2.17; 20.0.0-next.0 to <20.3.25; <=19.2.25

Timeline

  • 2026-06-15: disclosed: Advisory published
  • 2026-06-08: patched: Patch merged for version 20.3.x (PR #69197)
  • 2026-06-22: other: NVD entry published

References

Related threats