<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-09T09:01:43.718241+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-328553</id>
    <title>EUVD-2026-328553</title>
    <updated>2026-10-09T09:01:43.797231+00:00</updated>
    <content>EUVD-2026-328553</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-328553"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45617</id>
    <title>fkie_cve-2026-45617</title>
    <updated>2026-10-09T09:01:43.797271+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below, the built-in strip_html filter uses a regex containing four flawed lazy-quantified alternatives, leading to ReDoS via quadratic backtracking. When the input contains many &lt;script, &lt;style, or &lt;!-- opener tokens without matching closers, the V8 regex engine performs O(N²) backtracking, blocking the Node.js event loop. A single ~350 KB request ('&lt;script'.repeat(50000)) stalls the process for ~10 seconds; cost grows quadratically with input size. The default memoryLimit: Infinity does not bound regex CPU, and even when configured strip_html only charges str.length to the limit — the regex itself runs unbounded.  A single unauthenticated request containing crafted untrusted input can cause severe event-loop blocking and CPU amplification that saturates Node.js workers while bypassing memoryLimit protections. This issue has been fixed in version 10.26.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45617"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-r7g9-xpmj-5fcq</id>
    <title>GHSA-r7g9-xpmj-5fcq — LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex</title>
    <updated>2026-10-09T09:01:43.797313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: liquidjs</p>
<p>## Summary</p>
<p>The built-in `strip_html` filter in liquidjs uses a regex containing four lazy-quantified alternatives. When the input contains many `&lt;script`, `&lt;style`, or `&lt;!--` opener tokens without matching closers, the V8 regex engine performs O(N²) backtracking, blocking the Node.js event loop. A single ~350 KB request (`'&lt;script'.repeat(50000)`) stalls the process for ~10 seconds; cost grows quadratically with input size. The default `memoryLimit: Infinity` does not bound regex CPU, and even when configured `strip_html` only charges `str.length` to the limit — the regex itself runs unbounded.</p>
<p>## Details</p>
<p>The vulnerable filter is at `src/filters/html.ts:45-49`:</p>
<p>```ts
export function strip_html (this: FilterImpl, v: string) {
  const str = stringify(v)
  this.context.memoryLimit.use(str.length)
  return str.replace(/&lt;script[\s\S]*?&lt;\/script&gt;|&lt;style[\s\S]*?&lt;\/style&gt;|&lt;.*?&gt;|&lt;!--[\s\S]*?--&gt;/g, '')
}
```</p>
<p>The regex contains four lazy patterns:
1. `&lt;script[\s\S]*?&lt;\/script&gt;`
2. `&lt;style[\s\S]*?&lt;\/style&gt;`
3. `&lt;.*?&gt;`
4. `&lt;!--[\s\S]*?--&gt;`</p>
<p>For an input like `'&lt;script'.repeat(N)`, the engine encounters N starting `&lt;` positions. At each one it must lazily expand `[\s\S]*?` (and `.*?`) all the way to end-of-input searching for a closer that never appears, then fail and backtrack. Because each of the O(N) starts performs O(N) lazy-expansion work, total work is O(N²).</p>
<p>Reachability:
1. `strip_html` is a default-registered filter (exported from `src/filters/html.ts`, wired up via `src/fi…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-r7g9-xpmj-5fcq"/>
  </entry>
</feed>
