← Back to CVE search

CVE-2026-74794

Scriban

Description

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the hosting process.

CVSS 7.5EPSS 0.27799999999999997%Risk 0.77
View source
Published
2026-08-16 14:16:57
Affected versions
<6.6.0
Type
Library
Last modified
2026-08-17 17:16:52
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H