A vulnerability marked as problematic has been reported in harttle liquidjs up to 10.25.0 . Affected is the function String.prototype.replace . This manipulation causes denial of service. The identification of this vulnerability is CVE-2026-33287 . It is possible to initiate the attack remotely. There is no exploit available. It is suggested to upgrade the affected component.