Vulnerability Description
LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the date filter's strftime implementation parses width specifiers like %9999999d and forwards the captured width unchecked into pad()/padStart(), leading to memory and render limit bypass. In src/util/underscore.ts, the pad loop performs unbounded string concatenation without consulting the Context's memoryLimit or renderLimit, so a single small template ({{ x | date: '%5000000d' }}) produces megabytes of output and unbounded CPU. The memoryLimit and renderLimit options the docs (src/liquid-options.ts:87-92) advertise as DoS controls — and which the docstring explicitly mentions for strftime — are entirely bypassed. Exploitation can cause large memory allocations, high CPU usage, or OOM crashes per render. This issue has been fixed in version 10.26.0.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/harttle/liquidjs/commit/3129d46dc95efa357b00e5a57ee1af80a13d7
- https://github.com/harttle/liquidjs/releases/tag/v10.26.0
- https://github.com/harttle/liquidjs/security/advisories/GHSA-hh27-hf48-9f5q
- https://github.com/harttle/liquidjs/security/advisories/GHSA-hh27-hf48-9f5q
FAQ
What is CVE-2026-45357?
CVE-2026-45357 is a vulnerability with a CVSS score of 7.5 (HIGH). LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the date filter's strftime implementation parses width specifiers like %9999999...
How severe is CVE-2026-45357?
CVE-2026-45357 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-45357?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.