ShopperCove
Menu
All writingBlogTopicsCategoriesAboutRSS
Blog
Categories
Observability & SRE62All categories
About

Plate 38

  1. Blog

Angular router SSR: upgrade for RouterLink queryParams DoS (1 Oct 2026)

On 1 Oct 2026 Angular published GHSA-57xq-rjx2-v5xh: High DoS in @angular/router when SSR + RouterLink queryParamsHandling merge/preserve retain UrlTree query maps in heap. Patched in 21.2.25 and 22.2.1. Client-only SPAs unaffected. ShopperCove upgrade checklist only—no exploit payloads; no affiliate.

Aditya Challa·5 October 2026·4 min read

Summary
On this page
  1. Related links
  2. What the advisory says (high level)
  3. Who needs to patch
  4. Patched versions (upgrade target)
  5. Defensive checklist (no PoC)
  6. Bottom line
  7. Sources

Angular router SSR: upgrade for RouterLink queryParams DoS (1 Oct 2026)

On 1 October 2026, the Angular team published GitHub security advisory GHSA-57xq-rjx2-v5xh: a High denial-of-service issue in @angular/router when Server-Side Rendering (SSR) on Node.js retains merged or preserved query-parameter UrlTree data across RouterLink instances. ShopperCove did not patch a production Angular SSR app for this note and did not send test traffic against any site. The facts below come from that advisory, fix PR #70953, and npm package versions 21.2.25 / 22.2.1 (confirmed on the registry 5 October 2026). This is a defensive upgrade checklist, not an exploit guide—no attack payloads, no reproduction steps.

There is no affiliate link in this article.

Related links

  • https://www.shoppercove.com/blog/nextjs-16-3-8-security-release-2026
  • https://www.shoppercove.com/blog/chrome-154-0-8037-97-security-update-october-2026
  • https://www.shoppercove.com/blog/nodejs-26-lts-october-2026-schedule-change

What the advisory says (high level)

From GHSA-57xq-rjx2-v5xh:

  • Package: @angular/router (npm).
  • Severity: High (CVSS 8.2 per the advisory’s CVSS:4.0 vector).
  • Impact class: uncontrolled / unbounded resource consumption (CWE-400 / CWE-770)—heap growth that can crash the SSR worker with an out-of-memory failure under concurrent requests.
  • Not a data-theft bug: the advisory’s impact metrics list Confidentiality and Integrity as None; Availability as High on the vulnerable system.
  • Client-only SPAs: pure client-side Angular apps without SSR are not vulnerable under this advisory.

Who needs to patch

You are in scope only if all of these match (per the advisory’s preconditions—described here without attack recipes):

  1. The app uses SSR on Node.js / V8.
  2. Server-rendered RouterLinks use queryParamsHandling: 'merge' or 'preserve' (per link or via defaultQueryParamsHandling).
  3. Edge proxies forward long query strings to Node rather than rejecting them early.
  4. Multiple SSR renders can overlap in the same worker (slow resolvers / external fetches raise the window).

Affected version ranges (advisory):

  • >= 22.0.0, < 22.2.1
  • >= 21.2.0, < 21.2.25

Not affected: versions before 21.2.0 (including Angular 20.x LTS and 21.1.x) for this specific UrlTree retention issue.

Patched versions (upgrade target)

LineMinimum patched @angular/router
v2121.2.25
v2222.2.1

Both versions resolve on the npm registry as of 5 October 2026. Prefer your normal Angular update path (ng update / aligned @angular/* set) so peer packages stay on the same patch train—do not leave router alone on a mismatched minor if your workspace policy forbids it.

The fix (PR #70953) stops pinning intermediate UrlTree / query-map objects for the lifetime of each SSR request; links compute what they need for href and discard the intermediates.

Defensive checklist (no PoC)

  1. Inventory: npm ls @angular/router (or lockfile search). If you are on 21.2.0–21.2.24 or 22.0.0–22.2.0 and ship SSR, schedule the patch.
  2. Upgrade to 21.2.25 or 22.2.1 (or newer on that line) in a staging environment first; run your existing SSR smoke suite.
  3. Config hygiene (even after patch): avoid blanket defaultQueryParamsHandling: 'merge'|'preserve' on SSR pages when links only need a few explicit [queryParams] bindings—the advisory recommends binding only parameters each link needs.
  4. Edge limits: keep reverse-proxy / WAF request-line or query-length limits sane so oversized query strings never reach the Node worker. Exact knobs differ by Nginx/ALB/Cloudflare; use your platform’s docs, not copied attack strings.
  5. Do not treat raising --max-old-space-size as a substitute for the patch—the advisory lists it only as temporary headroom.

ShopperCove did not change production Angular versions for this article. Follow the advisory and your release process.

Bottom line

GHSA-57xq-rjx2-v5xh (1 Oct 2026) is a High SSR heap DoS in @angular/router when merge/preserve query handling keeps large query maps alive across RouterLinks. Patch to 21.2.25 or 22.2.1. Client-only apps without SSR are out of scope. Read the official advisory—do not chase third-party “PoC” posts.

Sources

  • https://github.com/angular/angular/security/advisories/GHSA-57xq-rjx2-v5xh
  • https://github.com/angular/angular/pull/70953
  • https://github.com/angular/angular/issues/70908
  • https://registry.npmjs.org/@angular/router/21.2.25
  • https://registry.npmjs.org/@angular/router/22.2.1
angularssrrouterlinksecurityghsa-57xq-rjx2-v5xhdenial of servicenode.js

Lab evidence

What I found running this

Sources read 5 Oct 2026: GitHub advisory GHSA-57xq-rjx2-v5xh; fix PR #70953; npm @angular/router 21.2.25 and 22.2.1 via registry. No SSR app patched on ShopperCove; no PoC requests sent. Defensive upgrade framing only.

Notes when a lab post goes up

Occasional email for new hands-on reviews. No sequence and no sponsors.

Related links

  • Plate 66

    Next.js 16.3.8 security release: SSRF, cache, and OG routes (and the earlier next/og RCE)

    Next.js 16.3.8 (30 Sep 2026) covers image SSRF and cache bugs. CVE-2026-94545, the next/og RCE, was patched in 16.3.6 and is not a 16.3.8 fix.

    3 Oct 2026

  • Plate 41

    React 19.3 View Transitions & Fragment Refs: Frontend Guide (2026)

    2 Oct 2026

  • Plate 34

    ast.literal_eval vs json.loads: Localhost Lab

    1 Oct 2026

On this page

  1. Related links
  2. What the advisory says (high level)
  3. Who needs to patch
  4. Patched versions (upgrade target)
  5. Defensive checklist (no PoC)
  6. Bottom line
  7. Sources
All writingBlogCategoriesTopicsAboutPrivacyRSS

© 2026 ShopperCove