CVE-2026-45617 - LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
CVE ID :CVE-2026-45617
Published : June 17, 2026, 10:14 p.m. | 1 hour, 24 minutes ago
Description :LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the built-in strip_html filter uses a regex containing four flawed lazy-quantified alternatives, leading to ReDoS via quadratic backtracking. When the input contains many Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 17, 2026, 10:14 p.m. | 1 hour, 24 minutes ago
Description :LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the built-in strip_html filter uses a regex containing four flawed lazy-quantified alternatives, leading to ReDoS via quadratic backtracking. When the input contains many Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...