CVE-2026-54268
Last modified
CVE-2026-54268 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. EPSS estimates a 0.33% chance of exploitation in the next 30 days.
Description
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, a Denial of Service (DoS) vulnerability exists in the @angular/common package of the Angular framework. The formatDate function, which is also utilized by the standard Angular DatePipe, does not properly limit or validate the length of the format parameter. When parsing a maliciously crafted, excessively long date format string (e.g., a repeating pattern or very large string), the internal parser splits the string iteratively using a regular expression loop. This results in uncontrolled resource consumption (high CPU utilization and excessive memory allocations), leading to a Denial of Service (DoS). This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Angular | Angular | <= 19.2.25 |
| Angular | Angular | >= 20.0.0, < 20.3.25 |
| Angular | Angular | >= 21.0.0, < 21.2.17 |
| Angular | Angular | >= 22.0.0, < 22.0.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-54268?
How severe is CVE-2026-54268?
How do I fix CVE-2026-54268?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-54262Wagtail is an open source content management system built on…4.3
- CVE-2026-54263Wagtail is an open source content management system built on…7.3
- CVE-2026-54264Angular is a development platform for building mobile and de…6.1
- CVE-2026-54265Angular is a development platform for building mobile and de…6.1
- CVE-2026-54266Angular is a development platform for building mobile and de…6.1
- CVE-2026-54267Angular is a development platform for building mobile and de…6.1
- CVE-2026-54269protobufjs compiles protobuf definitions into JavaScript (JS…5.3
- CVE-2026-5427The Kubio plugin for WordPress is vulnerable to Arbitrary Fi…5.3
- CVE-2026-54270protobufjs compiles protobuf definitions into JavaScript (JS…5.3
- CVE-2026-54271protobufjs-cli is the command line add-on for protobuf.js. P…8.2
- CVE-2026-54272ip-address is a library for parsing and manipulating IPv4 an…6.9
- CVE-2026-54273AIOHTTP is an asynchronous HTTP client/server framework for …7.5
Are you affected by CVE-2026-54268?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
