Vulnerability library
Security checkJuly 09, 2026

LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmliquidjs

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The built-in strip_html filter in liquidjs uses a regex containing four lazy-quantified alternatives. When the input contains many <script, <style, or <!-- opener tokens without matching closers, the V8 regex engine performs O(N²) backtracking, blocking the Node.js event loop. A single ~350 KB request ('<script'.repeat(50000)) stalls the process for ~10 seconds; cost grows quadratically with input size.

Recommendation

Update the liquidjs package to the latest compatible version. Followings are version details:

  • Affected version(s): < 10.26.0
  • Patched version(s): 10.26.0

References

Could your website be exposed too?

SmartScanner can check your website for LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 09, 2026