Plate 38
Angular router SSR: upgrade for RouterLink queryParams DoS (1 Oct 2026)
On 1 Oct 2026 Angular published GHSA-57xq-rjx2-v5xh: High DoS in @angular/router when SSR + RouterLink queryParamsHandling merge/preserve retain UrlTree query maps in heap. Patched in 21.2.25 and 22.2.1. Client-only SPAs unaffected. ShopperCove upgrade checklist only—no exploit payloads; no affiliate.
Aditya Challa4 min read
Angular router SSR: upgrade for RouterLink queryParams DoS (1 Oct 2026)
On 1 October 2026, the Angular team published GitHub security advisory GHSA-57xq-rjx2-v5xh: a High denial-of-service issue in @angular/router when Server-Side Rendering (SSR) on Node.js retains merged or preserved query-parameter UrlTree data across RouterLink instances. ShopperCove did not patch a production Angular SSR app for this note and did not send test traffic against any site. The facts below come from that advisory, fix PR #70953, and npm package versions 21.2.25 / 22.2.1 (confirmed on the registry 5 October 2026). This is a defensive upgrade checklist, not an exploit guide—no attack payloads, no reproduction steps.
There is no affiliate link in this article.
Related links
- https://www.shoppercove.com/blog/nextjs-16-3-8-security-release-2026
- https://www.shoppercove.com/blog/chrome-154-0-8037-97-security-update-october-2026
- https://www.shoppercove.com/blog/nodejs-26-lts-october-2026-schedule-change
What the advisory says (high level)
From GHSA-57xq-rjx2-v5xh:
- Package:
@angular/router(npm). - Severity: High (CVSS 8.2 per the advisory’s CVSS:4.0 vector).
- Impact class: uncontrolled / unbounded resource consumption (CWE-400 / CWE-770)—heap growth that can crash the SSR worker with an out-of-memory failure under concurrent requests.
- Not a data-theft bug: the advisory’s impact metrics list Confidentiality and Integrity as None; Availability as High on the vulnerable system.
- Client-only SPAs: pure client-side Angular apps without SSR are not vulnerable under this advisory.
Who needs to patch
You are in scope only if all of these match (per the advisory’s preconditions—described here without attack recipes):
- The app uses SSR on Node.js / V8.
- Server-rendered
RouterLinks usequeryParamsHandling: 'merge'or'preserve'(per link or viadefaultQueryParamsHandling). - Edge proxies forward long query strings to Node rather than rejecting them early.
- Multiple SSR renders can overlap in the same worker (slow resolvers / external fetches raise the window).
Affected version ranges (advisory):
>= 22.0.0, < 22.2.1>= 21.2.0, < 21.2.25
Not affected: versions before 21.2.0 (including Angular 20.x LTS and 21.1.x) for this specific UrlTree retention issue.
Patched versions (upgrade target)
| Line | Minimum patched @angular/router |
|---|---|
| v21 | 21.2.25 |
| v22 | 22.2.1 |
Both versions resolve on the npm registry as of 5 October 2026. Prefer your normal Angular update path (ng update / aligned @angular/* set) so peer packages stay on the same patch train—do not leave router alone on a mismatched minor if your workspace policy forbids it.
The fix (PR #70953) stops pinning intermediate UrlTree / query-map objects for the lifetime of each SSR request; links compute what they need for href and discard the intermediates.
Defensive checklist (no PoC)
- Inventory:
npm ls @angular/router(or lockfile search). If you are on 21.2.0–21.2.24 or 22.0.0–22.2.0 and ship SSR, schedule the patch. - Upgrade to 21.2.25 or 22.2.1 (or newer on that line) in a staging environment first; run your existing SSR smoke suite.
- Config hygiene (even after patch): avoid blanket
defaultQueryParamsHandling: 'merge'|'preserve'on SSR pages when links only need a few explicit[queryParams]bindings—the advisory recommends binding only parameters each link needs. - Edge limits: keep reverse-proxy / WAF request-line or query-length limits sane so oversized query strings never reach the Node worker. Exact knobs differ by Nginx/ALB/Cloudflare; use your platform’s docs, not copied attack strings.
- Do not treat raising
--max-old-space-sizeas a substitute for the patch—the advisory lists it only as temporary headroom.
ShopperCove did not change production Angular versions for this article. Follow the advisory and your release process.
Bottom line
GHSA-57xq-rjx2-v5xh (1 Oct 2026) is a High SSR heap DoS in @angular/router when merge/preserve query handling keeps large query maps alive across RouterLinks. Patch to 21.2.25 or 22.2.1. Client-only apps without SSR are out of scope. Read the official advisory—do not chase third-party “PoC” posts.
Sources
Lab evidence
What I found running this
Sources read 5 Oct 2026: GitHub advisory GHSA-57xq-rjx2-v5xh; fix PR #70953; npm @angular/router 21.2.25 and 22.2.1 via registry. No SSR app patched on ShopperCove; no PoC requests sent. Defensive upgrade framing only.
Related links
Plate 66
Next.js 16.3.8 security release: SSRF, cache, and OG routes (and the earlier next/og RCE)
Next.js 16.3.8 (30 Sep 2026) covers image SSRF and cache bugs. CVE-2026-94545, the next/og RCE, was patched in 16.3.6 and is not a 16.3.8 fix.
3 Oct 2026
Plate 41
React 19.3 View Transitions & Fragment Refs: Frontend Guide (2026)
2 Oct 2026
Plate 34
ast.literal_eval vs json.loads: Localhost Lab
1 Oct 2026