CVE-2026-33939 is a high-severity Denial of Service (DoS) vulnerability affecting Handlebars versions 4.0.0 through 4.7.8, allowing an attacker to crash a Node.js process by supplying a crafted template with unregistered decorator syntax. Rated 7.5 CVSS (AV:N/AC:L/A:H), it has a network attack vector and low attack complexity, requiring no privileges or user interaction to achieve a complete loss of availability. There is no evidence of active exploitation, and public exploit code is not available in common databases like Metasploit or ExploitDB. Despite minimal community discussion, upgrading to Handlebars version 4.7.9 or implementing workarounds such as try/catch blocks or input validation is recommended to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, < 4.7.9CPE matchmatch criteria | cpe:2.3:a:handlebarsjs:handlebars:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.