REDHAT-BUG-2452508: High severity Handlebars Handlebars vulnerability

Published Mar 27, 2026
·
Updated

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, when a Handlebars template contains decorator syntax referencing an unregistered decorator (e.g. {{n}}), the compiled template calls lookupProperty(decorators, "n"), which returns undefined. The runtime then immediately invokes the result as a function, causing an unhandled TypeError: ... is not a function that crashes the Node.js process. Any application that compiles user-supplied templates without wrapping the call in a try/catch is vulnerable to a single-request Denial of Service. Version 4.7.9 fixes the issue. Some workarounds are available. Wrap compilation and rendering in try/catch. Validate template input before passing it to compile(); reject templates containing decorator syntax ({{...}}) if decorators are not used in your application. Use the pre-compilation workflow; compile templates at build time and serve only pre-compiled templates; do not call compile() at request time.

Affected Software

2 affected components
Handlebars Handlebars>=4.0.0<=4.7.8
Handlebars Handlebars=4.7.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Handlebars to a version that resolves this vulnerability.

    Fixed in 4.7.9
  2. Configuration

    Use the pre-compilation workflow: compile templates at build time and serve only pre-compiled templates; do not call `compile()` at request time.

    Handlebars template compilation workflow request-time template compilation (compile()) = disabled
  3. Configuration

    Validate template input before passing it to `compile()`; reject templates containing decorator syntax (`{{*...}}`) if decorators are not used in your application.

    Handlebars template input validation decorator syntax allowance = reject `{{*...}}` when decorators are not used
  4. Configuration

    Wrap compilation and rendering in `try/catch` to prevent unhandled `TypeError: ... is not a function` from crashing the Node.js process.

    Node.js runtime handling of Handlebars compilation/rendering error handling for compilation and rendering = wrap in try/catch

Event History

Mar 27, 2026
Data Sourced
via Red Hat·10:02 PM
DescriptionSeverityAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203