CVE-2026-34166 affects LiquidJS, a JavaScript template engine compatible with Shopify and GitHub Pages. The vulnerability exists in the replace filter function, which miscalculates memory usage when the memoryLimit option is enabled, allowing attackers to bypass denial-of-service protections through a memory amplification attack with up to 2,500x magnification. The vulnerability has a CVSS score of 5.3 (Medium) with a network-based attack vector requiring no authentication or user interaction. The attack complexity is low, and the impact is limited to availability; the attacker can create out-of-memory conditions by crafting template content with patterns that cause quadratic output growth, though no confidentiality or integrity impact exists. This vulnerability is not currently being actively exploited in the wild, does not appear on the Known Exploited Vulnerabilities catalog, and has minimal community attention based on the EPSS score of 0.00016. The fix is available in LiquidJS version 10.25.3, and organizations should prioritize updating to eliminate this denial-of-service risk, particularly if they allow untrusted users to create or modify templates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.25.3CPE matchmatch criteria | cpe:2.3:a:liquidjs:liquidjs:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.