← Zurück zur CVE-Suche

CVE-2026-74783

Scriban

Beschreibung

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable StackOverflowException that immediately terminates the host process.

CVSS 7.5EPSS 0.27799999999999997%Risiko 0.77
Quelle öffnen
Veröffentlicht
2026-08-16 14:16:56
Betroffene Versionen
>=6.6.0,<=7.2.0
Typ
Bibliothek
Zuletzt geändert
2026-08-17 17:16:52
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H