Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} or {% else %} block and no terminating {% endcase %} tag, Python Liquid hangs in an infinite loop at parse time because liquid.TokenStream.eof did not give the EOF token matching kind and value fields, allowing malicious template authors to craft templates for a denial of service attack. This issue is fixed in version 2.2.1.
Metrics
Affected Vendors & Products
References
History
Tue, 14 Jul 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Jul 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jg-rp
Jg-rp liquid |
|
| Vendors & Products |
Jg-rp
Jg-rp liquid |
Thu, 09 Jul 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.1, given a malformed {% case %} tag without an associated {% when %} or {% else %} block and no terminating {% endcase %} tag, Python Liquid hangs in an infinite loop at parse time because liquid.TokenStream.eof did not give the EOF token matching kind and value fields, allowing malicious template authors to craft templates for a denial of service attack. This issue is fixed in version 2.2.1. | |
| Title | Python Liquid: Infinite loop when parsing malformed `{% case %}` tags | |
| Weaknesses | CWE-835 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-07-09T20:34:38.618Z
Updated: 2026-07-14T01:16:10.895Z
Reserved: 2026-06-17T16:44:40.996Z
Link: CVE-2026-55865
Updated: 2026-07-14T01:16:07.092Z
Status : Deferred
Published: 2026-07-09T21:16:56.277
Modified: 2026-07-14T02:16:56.407
Link: CVE-2026-55865
No data.