Which @angular/* package(s) are the source of the bug?
platform-server
Is this a regression?
No
Description
Angular SSR uses Domino for server-side HTML parsing.
Pathological mis-nested formatting markup can cause Domino's active formatting element reconstruction algorithm to repeatedly recreate an increasing number of stale formatting entries. This leads to super-linear DOM growth and can exhaust the Node.js heap from a comparatively small HTML input.
The issue is reproducible on current Domino main, including after the existing numeric attribute storage hardening (c5aa1eb), and does not depend on numeric attribute names.
For example:
let html = '';
for (let i = 0; i < 600; i++) {
html += `<p><b a${i}></p>`;
}
This generates an 8,290-byte input.
On Node.js 22.22.3 with:
current unpatched Domino main terminates with a fatal V8 heap OOM / SIGABRT.
An equal-size normally nested control succeeds:
let html = '';
for (let i = 0; i < 600; i++) {
html += `<p><b a${i}></b></p>`;
}
The issue is caused by repeated work in the active formatting reconstruction path rather than numeric attribute storage.
A fix and regression test are available in:
angular/domino#53
The fix bounds cumulative active-formatting reconstruction work relative to parser input. With the patch applied, the same pathological input is rejected with a controlled parser error and the Node.js process survives.
Please provide a link to a minimal reproduction of the bug
angular/domino#53
The PR contains a small safe regression test covering the same reconstruction path.
For the full impact reproduction, use the non-numeric pattern above with N = 600 and a Node.js heap limit of 128 MiB.
Please provide the exception or error you saw
Unpatched current Domino main:
signal: SIGABRT
heapOom: true
FATAL ERROR: Reached heap limit
Allocation failed - JavaScript heap out of memory
With angular/domino#53 applied:
Error: HTML parser active formatting reconstruction limit exceeded
The patched process remains alive and heapOom is false.
Please provide the environment you discovered this bug in
Node.js: 22.22.3
OS: Linux x64
Domino current main:
1929b1e
Existing numeric attribute hardening already present:
c5aa1eb
Anything else?
Fix PR:
angular/domino#53
More details :
https://issuetracker.google.com/issues/563332595
Validation performed against current Domino main:
- 8,290-byte non-numeric payload reproduces fatal heap exhaustion at a 128 MiB Node.js heap limit.
- Equal-size normal control succeeds.
- Issue remains reproducible after the numeric attribute storage fix.
- Patched version converts the fatal OOM into a controlled parser error.
- Incremental parsing was tested with chunk sizes of 1, 2, 7, 16, 64, 256, and 4096 bytes.
- Normal incremental parsing still succeeds.
- Regression fails before the fix and passes afterward.
- Full current Domino test suite with the patch:
2238 passing.
Which @angular/* package(s) are the source of the bug?
platform-server
Is this a regression?
No
Description
Angular SSR uses Domino for server-side HTML parsing.
Pathological mis-nested formatting markup can cause Domino's active formatting element reconstruction algorithm to repeatedly recreate an increasing number of stale formatting entries. This leads to super-linear DOM growth and can exhaust the Node.js heap from a comparatively small HTML input.
The issue is reproducible on current Domino
main, including after the existing numeric attribute storage hardening (c5aa1eb), and does not depend on numeric attribute names.For example:
This generates an 8,290-byte input.
On Node.js 22.22.3 with:
current unpatched Domino
mainterminates with a fatal V8 heap OOM /SIGABRT.An equal-size normally nested control succeeds:
The issue is caused by repeated work in the active formatting reconstruction path rather than numeric attribute storage.
A fix and regression test are available in:
angular/domino#53
The fix bounds cumulative active-formatting reconstruction work relative to parser input. With the patch applied, the same pathological input is rejected with a controlled parser error and the Node.js process survives.
Please provide a link to a minimal reproduction of the bug
angular/domino#53
The PR contains a small safe regression test covering the same reconstruction path.
For the full impact reproduction, use the non-numeric pattern above with
N = 600and a Node.js heap limit of 128 MiB.Please provide the exception or error you saw
Unpatched current Domino
main:With angular/domino#53 applied:
The patched process remains alive and
heapOomis false.Please provide the environment you discovered this bug in
Anything else?
Fix PR:
angular/domino#53
More details :
https://issuetracker.google.com/issues/563332595
Validation performed against current Domino
main:2238 passing.