{"apiVersion":"1.0","identifier":"CVE-2026-74795","description":"Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expression depth limit (the ExpressionDepthLimit property in ParserOptions defaults to null/disabled), so an attacker who controls template input can supply a deeply nested template (e.g., thousands of nested parentheses or blocks) that exhausts thread stack space and raises a StackOverflowException. Because a StackOverflowException cannot be caught in .NET, this causes immediate, unrecoverable termination of the hosting process, resulting in a denial of service. Applications that process untrusted or user-supplied templates can be exploited remotely without authentication.","publishedAt":"2026-08-16T14:16:57","lastModifiedAt":"2026-08-17T16:17:48","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-74795","cvssScore":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","epssProbability":0.00318,"riskScore":0.77,"affectedProduct":"Scriban","affectedVersions":"<6.6.0","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-74795","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-74795","en":"https://www.redsauce.net/en/cves/CVE-2026-74795","fr":"https://www.redsauce.net/fr/cves/CVE-2026-74795","pt":"https://www.redsauce.net/pt/cves/CVE-2026-74795","de":"https://www.redsauce.net/de/cves/CVE-2026-74795","sk":"https://www.redsauce.net/sk/cves/CVE-2026-74795","el":"https://www.redsauce.net/el/cves/CVE-2026-74795"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-74795"}}