{"id":"GHSA-p3vc-36g9-x9gr","summary":"@angular/common: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)","details":"A Denial of Service (DoS) vulnerability exists in the `@angular/common` package of Angular. The `formatNumber` function, which is also utilized by `DecimalPipe`, `PercentPipe`, and `CurrencyPipe`, does not properly validate the upper bounds of the `digitsInfo` parameter. Specifically, the minimum and maximum fraction digits parsed from the `digitsInfo` string (e.g., `1.2-4`) are converted to integers and used without limits.\n\nWhen parsing a maliciously crafted `digitsInfo` string with excessively large fraction digit values (e.g., `1.200000000-200000000`), the internal `roundNumber` function attempts to pad the digits array to match the requested fraction size. This results in an unbounded loop that repeatedly pushes elements into an array.\n\n### Impact\n\nSuccessful exploitation of this vulnerability allows an attacker to trigger resource exhaustion, leading to a Denial of Service (DoS):\n\n* **Server-Side Rendering (SSR):** In applications using SSR (e.g., `@angular/ssr`), an attacker can crash the Node.js server process due to a `JavaScript heap out of memory` error. This affects the availability of the application for all users.  \n* **Client-Side Rendering (CSR):** In standard client-side applications, the unbounded loop will block the main thread, freezing the user's browser tab and making it unresponsive.\n\n### Attack Preconditions\n\nFor this vulnerability to be exploitable, the following conditions must be met:\n\n1. **Vulnerable Component Usage:** The application must use Angular's number formatting utilities, such as the `formatNumber` function directly, or via template pipes (`DecimalPipe`, `PercentPipe`, `CurrencyPipe`).  \n2. **Attacker-Controlled Parameter:** The `digitsInfo` parameter passed to these utilities must be customizable or directly controlled by untrusted user input (e.g., parsed from query parameters, user preference settings, or API responses that accept user-defined formatting options). If `digitsInfo` is trusted or limited to a known, defined range for its value, the vulnerability is not exploitable by external attackers.\n\n### Patches\n- 22.0.0-rc.2\n- 21.2.15\n- 20.3.22\n- 19.2.23\n\n### Credits\nThis vulnerability was discovered and reported by [CodeMender from Google DeepMind](https://deepmind.google/blog/introducing-codemender-an-ai-agent-for-code-security/).","aliases":["CVE-2026-50171"],"modified":"2026-07-17T21:14:42.309289615Z","published":"2026-06-15T16:52:30Z","database_specific":{"github_reviewed_at":"2026-06-15T16:52:30Z","nvd_published_at":"2026-06-22T18:16:42Z","cwe_ids":["CWE-400","CWE-834"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/angular/angular/security/advisories/GHSA-p3vc-36g9-x9gr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50171"},{"type":"WEB","url":"https://github.com/angular/angular/pull/68840"},{"type":"PACKAGE","url":"https://github.com/angular/angular"}],"affected":[{"package":{"name":"@angular/common","ecosystem":"npm","purl":"pkg:npm/%40angular/common"},"ranges":[{"type":"SEMVER","events":[{"introduced":"22.0.0-next.0"},{"fixed":"22.0.0-rc.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p3vc-36g9-x9gr/GHSA-p3vc-36g9-x9gr.json"}},{"package":{"name":"@angular/common","ecosystem":"npm","purl":"pkg:npm/%40angular/common"},"ranges":[{"type":"SEMVER","events":[{"introduced":"20.0.0-next.0"},{"fixed":"20.3.22"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p3vc-36g9-x9gr/GHSA-p3vc-36g9-x9gr.json"}},{"package":{"name":"@angular/common","ecosystem":"npm","purl":"pkg:npm/%40angular/common"},"ranges":[{"type":"SEMVER","events":[{"introduced":"19.0.0-next.0"},{"fixed":"19.2.23"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p3vc-36g9-x9gr/GHSA-p3vc-36g9-x9gr.json"}},{"package":{"name":"@angular/common","ecosystem":"npm","purl":"pkg:npm/%40angular/common"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"18.2.14"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p3vc-36g9-x9gr/GHSA-p3vc-36g9-x9gr.json"}},{"package":{"name":"@angular/common","ecosystem":"npm","purl":"pkg:npm/%40angular/common"},"ranges":[{"type":"SEMVER","events":[{"introduced":"21.0.0-next.0"},{"fixed":"21.2.15"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-p3vc-36g9-x9gr/GHSA-p3vc-36g9-x9gr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}