CVE-2026-45617
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/06/2026
Last modified:
22/06/2026
Description
LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the built-in strip_html filter uses a regex containing four flawed lazy-quantified alternatives, leading to ReDoS via quadratic backtracking. When the input contains many
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



