
CVE-2026-33939 has been published based on trace37 research and findings. Denial of Service in Handlebars.js (4.0.0 through 4.7.8), patched in 4.7.9. Handlebars has over 2 million weekly downloads on npm. I discovered that referencing an unregistered decorator in a Handlebars template (e.g. {{*n}}) crashes the Node.js process with an unhandled TypeError. A single malicious request to any endpoint compiling user-supplied templates takes down the server. The root cause: the compiled code calls the result of a property lookup as a function without checking if it exists — something Handlebars already handles correctly for missing helpers, but not for decorators. The maintainer patched it promptly. Full writeup: https://labs.trace37.com/cves/cve-2026-33939/ GitHub Advisory: https://github.com/handlebars-lang/handlebars.js/security/advisories/GHSA-9cx6-37pm-9jff If you use Handlebars in production, upgrade to 4.7.9. #CVE #security #vulnerability #nodejs #opensource
Post summary
CVE‑2026‑33939 causes a denial‑of‑service in Handlebars.js when using an unregistered decorator. The vulnerability has been patched in version 4.7.9; upgrading is recommended.

