Executive brief
Python Liquid is a software library used to process and display content using the Liquid template language. A flaw in how the library handles certain malformed code tags can cause the system to enter an infinite loop during processing. This could allow a malicious user to crash the application or make it unresponsive, leading to a denial of service.
Technical details
A vulnerability classified as CWE-835 (Loop with Unreachable Exit Condition) exists in Python Liquid prior to version 2.2.1. The issue is triggered when the parser encounters a malformed '{% case %}' tag that lacks associated '{% when %}' or '{% else %}' blocks and is missing a terminating '{% endcase %}' tag. This occurs because the 'liquid.TokenStream.eof' attribute did not return an EOF token with matching kind and value fields, preventing the parser from identifying the end of the stream. An attacker with the ability to provide or edit templates can exploit this to cause a permanent hang (Denial of Service) at parse time. The issue is resolved in version 2.2.1 by correcting the EOF token definition.
Affected products
- jg-rp liquid < 2.2.1
Timeline
- 2026-06-16: patched: Version 2.2.1 released
- 2026-06-16: advisory: GitHub Security Advisory GHSA-vq2f-vcc9-j8mv published
- 2026-07-09: disclosed: CVE-2026-55865 published to NVD