harttle liquidjs是harttle的嵌入式Web服务器。 harttle liquidjs 10.25.7及之前版本存在安全漏洞,该漏洞源于日期过滤器的strftime实现中未检查宽度说明符,将捕获的宽度无限制传入pad()/padStart(),导致内存和渲染限制绕过,可能造成大量内存分配、CPU使用率高或内存耗尽崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-45617 | 7.5 HIGH | LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex |
| CVE-2026-44645 | 6.5 MEDIUM | LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body |
| CVE-2026-44644 | 6.1 MEDIUM | LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS |
| CVE-2026-44646 | 5.3 MEDIUM | LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Cont |
No comments yet