Skip to content

Angular SSR: Domino active formatting reconstruction can cause heap exhaustion #70926

Description

@Adyej999

Which @angular/* package(s) are the source of the bug?

platform-server

Is this a regression?

No

Description

Angular SSR uses Domino for server-side HTML parsing.

Pathological mis-nested formatting markup can cause Domino's active formatting element reconstruction algorithm to repeatedly recreate an increasing number of stale formatting entries. This leads to super-linear DOM growth and can exhaust the Node.js heap from a comparatively small HTML input.

The issue is reproducible on current Domino main, including after the existing numeric attribute storage hardening (c5aa1eb), and does not depend on numeric attribute names.

For example:

let html = '';

for (let i = 0; i < 600; i++) {
  html += `<p><b a${i}></p>`;
}

This generates an 8,290-byte input.

On Node.js 22.22.3 with:

--max-old-space-size=128

current unpatched Domino main terminates with a fatal V8 heap OOM / SIGABRT.

An equal-size normally nested control succeeds:

let html = '';

for (let i = 0; i < 600; i++) {
  html += `<p><b a${i}></b></p>`;
}

The issue is caused by repeated work in the active formatting reconstruction path rather than numeric attribute storage.

A fix and regression test are available in:

angular/domino#53

The fix bounds cumulative active-formatting reconstruction work relative to parser input. With the patch applied, the same pathological input is rejected with a controlled parser error and the Node.js process survives.

Please provide a link to a minimal reproduction of the bug

angular/domino#53

The PR contains a small safe regression test covering the same reconstruction path.

For the full impact reproduction, use the non-numeric pattern above with N = 600 and a Node.js heap limit of 128 MiB.

Please provide the exception or error you saw

Unpatched current Domino main:

signal: SIGABRT
heapOom: true

FATAL ERROR: Reached heap limit
Allocation failed - JavaScript heap out of memory

With angular/domino#53 applied:

Error: HTML parser active formatting reconstruction limit exceeded

The patched process remains alive and heapOom is false.

Please provide the environment you discovered this bug in

Node.js: 22.22.3
OS: Linux x64

Domino current main:
1929b1e

Existing numeric attribute hardening already present:
c5aa1eb

Anything else?

Fix PR:

angular/domino#53
More details :
https://issuetracker.google.com/issues/563332595

Validation performed against current Domino main:

  • 8,290-byte non-numeric payload reproduces fatal heap exhaustion at a 128 MiB Node.js heap limit.
  • Equal-size normal control succeeds.
  • Issue remains reproducible after the numeric attribute storage fix.
  • Patched version converts the fatal OOM into a controlled parser error.
  • Incremental parsing was tested with chunk sizes of 1, 2, 7, 16, 64, 256, and 4096 bytes.
  • Normal incremental parsing still succeeds.
  • Regression fails before the fix and passes afterward.
  • Full current Domino test suite with the patch: 2238 passing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: serverIssues related to server-side renderinggemini-triagedLabel noting that an issue has been triaged by gemini

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions