liquidjs is vulnerable to Regular Expression Denial of Service (ReDoS)
65
Medium Risk
The strip_html filter stripped markup with a global regex whose backtracking grew quadratically on inputs with many unclosed tag openers. An attacker who can drive large translated strings through that filter can pin CPU for extended periods and deny service. The implementation is now a single linear scan over raw-text and generic tag blocks with explicit open/close handling. Tests bound runtime on adversarial PoC strings.
You are affected if you are using a version that falls within the vulnerable range.
liquidjs is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 10.0.0 - 10.25.7.
Upgrade the liquidjs library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant