CVE-2026-33285Disclosure(liquidjs / liquidjs)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's `memoryLimit` security mechanism can be completely bypassed by using reverse range expressions (e.g., `(100000000..1)`), allowing an attacker to allocate unlimited memory. Combined with a string flattening operation (e.g., `replace` filter), this causes a V8 Fatal error that crashes the Node.js process, resulting in complete denial of service from a single HTTP request. Version 10.25.1 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-400

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • liquidjs

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
liquidjs

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-26: 2Technical Details · 2026-03-26: 203-26
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33285 LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.1, LiquidJS's `memoryLimit` security mechanism can be compl… https://www.cve.org/CVERecord?id=CVE-2026-33285

    Post summary

    The CVE‑2026‑33285 vulnerability involves LiquidJS’s memoryLimit enforcement being ineffective in versions before 10.25.1, indicating a potential security flaw that has been formally disclosed.

    00010133
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33285 - LiquidJS: memoryLimit Bypass through Negative Range Values Leads to Process Crash Intel Report: https://ift.tt/pOMmj3v

    Post summary

    The alert announces the new vulnerability CVE-2026-33285 in LiquidJS, outlining a memoryLimit bypass via negative range values that can crash the process, but it provides no exploit, patch, or PoC details.

    0000056
    286 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appliquidjsliquidjs-node.js-

Explore more