Thanks to visit codestin.com
Credit goes to github.com

Skip to content

[Backport 20.3.x] fix(common): Limits date format string length - #69197

Merged
atscott merged 1 commit into
angular:20.3.xfrom
SkyZeroZx:backport-69000-to-20.3.x
Jun 8, 2026
Merged

[Backport 20.3.x] fix(common): Limits date format string length#69197
atscott merged 1 commit into
angular:20.3.xfrom
SkyZeroZx:backport-69000-to-20.3.x

Conversation

@SkyZeroZx

Copy link
Copy Markdown
Contributor

Backport of #69000

Introduces a maximum length of 256 characters for date format strings.

This prevents potential Denial of Service (DoS) attacks by throwing an
`INVALID_DATE_FORMAT` error if an excessively long format string is
provided to `formatDate` or `DatePipe`, safeguarding against performance
degradation or application crashes.

(cherry picked from commit 35de6b3)
@pullapprove
pullapprove Bot requested a review from kirjs June 5, 2026 19:18
@angular-robot angular-robot Bot added the area: common Issues related to APIs in the @angular/common package label Jun 5, 2026
@ngbot ngbot Bot added this to the Backlog milestone Jun 5, 2026
@JeanMeche
JeanMeche removed the request for review from kirjs June 5, 2026 22:13
@JeanMeche JeanMeche added action: merge The PR is ready for merge by the caretaker target: lts This PR is targeting a version currently in long-term support labels Jun 5, 2026
@atscott
atscott merged commit 9f443bc into angular:20.3.x Jun 8, 2026
13 checks passed
@atscott

atscott commented Jun 8, 2026

Copy link
Copy Markdown
Contributor

This PR was merged into the repository. The changes were merged into the following branches:

@angular-automatic-lock-bot

Copy link
Copy Markdown

This pull request has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot Bot locked and limited conversation to collaborators Jul 9, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

action: merge The PR is ready for merge by the caretaker area: common Issues related to APIs in the @angular/common package target: lts This PR is targeting a version currently in long-term support

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants