PT-2026-73152 · Scriban · Scriban

·

CVE-2026-74784

·

Published

2026-05-19

·

Updated

2026-08-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Scriban versions prior to 7.2.0
Description A denial of service issue exists in the array.insert at() function. The function allocates unbounded null entries and fails to respect LoopLimit or LimitToString constraints. An attacker can provide a large index parameter to trigger an OutOfMemoryException, which crashes the host process in less than a second.
Recommendations Update to version 7.2.0 or later. As a temporary workaround, restrict the use of the array.insert at() function.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74784
GHSA-24C8-4792-22HX

Affected Products

Scriban