Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:npm/liquidjs

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-69222 is a high-severity vulnerability in harttle liquidjs, a JavaScript template engine. Prior to version 10.27.2, certain filters (join and array_to_sentence_string) incorrectly calculate resource usage, allowing crafted templates to cause excessive memory consumption. This can lead to process crashes due to exceeding memory limits. The issue is fixed in version 10.27.2.

Join the discussion

A high-severity infinite loop vulnerability exists in the LiquidJS template engine versions 10.26.0 through 10.27.0. The issue occurs in the strip_html filter when processing input strings containing a '<' character with no corresponding closing '>'. This causes the template rendering to hang indefinitely, resulting in a denial of service. The vulnerability is fixed in version 10.27.1.

Join the discussion

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templates. Version 10.26.0 patches the issue.

Join the discussion

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.1, the pop array filter at src/filters/array.ts allocated a full clone of its input array via [...toArray(v)] without calling this.context.memoryLimit.use(...), allowing a template render such as {{ huge_array | pop }} to allocate an O(N) clone of an attacker-influenced array outside the configured memoryLimit budget. This issue is fixed in version 10.27.1.

Join the discussion

CVE-2026-45357 is a high-severity vulnerability in harttle liquidjs, a JavaScript template engine. Versions 10.25.7 and below have an uncontrolled resource consumption issue in the date filter's strftime implementation. Specifically, large width specifiers like %9999999d cause unbounded string padding operations that bypass memory and render limits, leading to excessive memory use and CPU consumption. This can result in denial-of-service conditions such as out-of-memory crashes during template rendering. The issue is fixed in version 10.26.0.

Join the discussion

CVE-2026-44645 is a medium severity vulnerability in the LiquidJS template engine (versions 10.25.7 and below) where the renderLimit option intended to limit rendering time can be bypassed by using an empty {% for %} or {% tablerow %} loop body. This allows an attacker to cause uncontrolled resource consumption by iterating over large collections without triggering the time limit, resulting in denial of service by monopolizing the Node.js event-loop thread. The issue has been fixed in version 10.26.0.

Join the discussion

LiquidJS versions 10.25.7 and below contain a cross-site scripting (XSS) vulnerability in the strip_html filter. The filter fails to remove HTML tags containing newline characters due to a regex limitation, allowing malicious tags with embedded event handlers to bypass sanitization. This can lead to script execution when attacker-controlled input is rendered without additional HTML escaping. The issue is fixed in version 10.26.0.

Join the discussion

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular block reference in {% layout %} / {% block %} causes an infinite recursive loop, consuming all available memory (~4GB) and crashing the Node.js process with FATAL ERROR: JavaScript heap out of memory. This allows any user who can submit a Liquid template to perform a Denial of Service attack. This issue has been patched in version 10.25.7.

Join the discussion

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.25.3, liquidjs 10.25.0 documents root as constraining filenames passed to renderFile() and parseFile(), but top-level file loads do not enforce that boundary. A Liquid instance configured with an empty temporary directory as root can return the contents of arbitrary files. This vulnerability is fixed in 10.25.3.

Join the discussion

A vulnerability in LiquidJS versions prior to 10.25.4 allows template authors to bypass the ownPropertyOnly security option via the sort_natural filter. This enables unauthorized exposure of sensitive prototype-inherited properties, such as API keys and tokens, through a sorting side-channel attack. The issue is fixed in version 10.25.4.

Join the discussion

Showing 1 to 10 of 15 results

Filters:Package: pkg:npm/liquidjs
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses