PatchSiren cyber security CVE debrief
CVE-2026-41311 harttle CVE debrief
CVE-2026-41311 is a denial-of-service vulnerability in LiquidJS. A circular {% layout %}/{% block %} reference can trigger an infinite recursive loop, consuming available memory and crashing the Node.js process. The issue is fixed in LiquidJS 10.25.7, and teams that accept untrusted Liquid templates should prioritize upgrading and adding template validation controls.
- Vendor
- harttle
- Product
- liquidjs
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-09
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-09
- Advisory updated
- 2026-07-24
Who should care
Operators and developers using LiquidJS in Node.js applications, especially any service that renders user-supplied or tenant-supplied Liquid templates. Security teams should also review template submission paths and any build or preview systems that evaluate Liquid content.
Technical summary
The NVD record and GitHub advisory align on CWE-674 (Uncontrolled Recursion). In affected LiquidJS versions prior to 10.25.7, a circular block reference in {% layout %} and {% block %} can recurse indefinitely, eventually exhausting the JavaScript heap (described as around 4GB) and terminating the process with a fatal out-of-memory error. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, reflecting a network-reachable availability impact.
Defensive priority
High — the issue can be triggered by submitting a crafted template, and the result is process-level denial of service through memory exhaustion.
Recommended defensive actions
- Upgrade LiquidJS to version 10.25.7 or later.
- Inventory all applications and services that use LiquidJS, including preview, CMS, and build pipelines.
- Restrict who can submit or modify Liquid templates; treat untrusted templates as high risk.
- Add validation or policy checks to reject circular {% layout %}/{% block %} relationships before rendering.
- Run the renderer with process isolation and resource limits so a crash or memory spike is contained.
- Confirm deployed package versions and redeploy any pinned or vendored copies that still use a vulnerable release.
Evidence notes
The supplied official sources are consistent: the CVE description states the circular layout/block recursion issue and the fix in 10.25.7; the NVD record supplies the CVSS vector and CWE-674; the GitHub advisory, release tag v10.25.7, and commit e2311dfd6e82f73509308aa8a3a1fafc92e226f0 are the referenced remediation artifacts. The CVE was published and modified at 2026-05-09T04:16:21.913Z in the provided timeline.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-41311 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-41311
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-41311 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41311
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/harttle/liquidjs/commit/e2311dfd6e82f73509308aa8a3a1fafc92e226f0
-
Source reference
Unverified legacy reference
URL: https://github.com/harttle/liquidjs/releases/tag/v10.25.7
-
Source reference
Unverified legacy reference
URL: https://github.com/harttle/liquidjs/security/advisories/GHSA-4rc3-7j7w-m548
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.