
Upwind Security MDR@UpwindMDR
🚨High - Angular platform-server domino parser infinite loop DoS (CVE-2026-101895) In @angular/platform-server’s DOM emulation parser (domino), untrusted HTML with an incomplete DOCTYPE ending in whitespace before EOF hits an EOF handling branch that emits tokens without advancing the scanner state, causing an infinite loop. Remote attackers can trigger CPU/resource exhaustion (DoS). 👉Affected: @angular/platform-server (versions not specified)
0000048
309 followersView on X
