HIGH
Python Liquid: Infinite loop when parsing malformed `{% case %}` tags
Published Jul 9, 2026
7.1
HIGHCVSS 4.0
EPSS 0.45%
Description
Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} or {% else %} block and no terminating {% endcase %} tag, Python Liquid hangs in an infinite loop at parse time because liquid.TokenStream.eof did not give the EOF token matching kind and value fields, allowing malicious template authors to craft templates for a denial of service attack. This issue is fixed in version 2.2.1.
Affected products
-
Affected
- < 2.2.1
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42693 Advisory
- https://github.com/advisories/GHSA-vq2f-vcc9-j8mv Advisory
- https://github.com/jg-rp/liquid/commit/26db8931cf35e8433c1ca506fc32c3bb62f743d4 x_refsource_MISC
- https://github.com/jg-rp/liquid/releases/tag/v2.2.1 x_refsource_MISC
- https://github.com/jg-rp/liquid/security/advisories/GHSA-vq2f-vcc9-j8mv x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42693 | Advisory | |
| https://github.com/advisories/GHSA-vq2f-vcc9-j8mv | Advisory | |
| https://github.com/jg-rp/liquid/commit/26db8931cf35e8433c1ca506fc32c3bb62f743d4 | x_refsource_MISC | |
| https://github.com/jg-rp/liquid/releases/tag/v2.2.1 | x_refsource_MISC | |
| https://github.com/jg-rp/liquid/security/advisories/GHSA-vq2f-vcc9-j8mv | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 9, 2026
Updated Jul 14, 2026
Reserved Jun 17, 2026
Link CVE-2026-55865
CISA Vulnrichment
Updated Jul 14, 2026
Red Hat
No data
GitHub
Link GHSA-VQ2F-VCC9-J8MV