Back

HIGH

Python Liquid: Infinite loop when parsing malformed `{% case %}` tags

Published Jul 9, 2026

Description

Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} or {% else %} block and no terminating {% endcase %} tag, Python Liquid hangs in an infinite loop at parse time because liquid.TokenStream.eof did not give the EOF token matching kind and value fields, allowing malicious template authors to craft templates for a denial of service attack. This issue is fixed in version 2.2.1.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Jul 9, 2026
Updated Jul 14, 2026
Reserved Jun 17, 2026

CISA Vulnrichment

Updated Jul 14, 2026

NVD

Status Deferred
Modified Jul 14, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Jul 9, 2026
Updated Jul 14, 2026