CVE-2026-54268

EUVD-2026-38273
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. The formatDate function, which is also utilized by the standard Angular DatePipe, does not properly limit or validate the length of the format parameter. When parsing a maliciously crafted, excessively long date format string (e.g., a repeating pattern or very large string), the internal parser splits the string iteratively using a regular expression loop. This results in uncontrolled resource consumption (high CPU utilization and excessive memory allocations), leading to a Denial of Service (DoS). This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 25.19%
Affected Products (NVD)
VendorProductVersion
angularangular
𝑥
≤ 19.2.25
angularangular
20.0.0 ≤
𝑥
< 20.3.25
angularangular
21.0.0 ≤
𝑥
< 21.2.17
angularangular
22.0.0 ≤
𝑥
< 22.0.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
angular.js
bookworm
undetermined
bullseye
undetermined
bullseye (security)
undetermined
forky
undetermined
sid
undetermined
trixie
undetermined
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
angular.js
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
xenial
needs-triage