Description
The renderLimit option — documented in docs/source/tutorials/dos.md as the mechanism that “mitigates this by limiting the time consumed by each render() call” — can be fully bypassed by a {% for %} (or {% tablerow %}) tag whose body is empty.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 10.25.7
References
Could your website be exposed too?
SmartScanner can check your website for LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body and gives you actionable findings to investigate.
Start a free scanRelated Issues
- LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime) - CVE-2026-45357
- LiquidJS Has Memory Limit Bypass via Quadratic Amplification in `replace` Filter - CVE-2026-34166
- Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules - nitro - CVE-2026-44372
- Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules - CVE-2026-44372


