PT-2026-73153 · Scriban · Scriban

·

CVE-2026-74785

·

Published

2026-03-24

·

Updated

2026-08-17

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Scriban versions prior to 7.0.0
Description Three distinct denial-of-service issues exist in expression evaluation that bypass safety controls. These issues involve unbounded string multiplication, uncontrolled BigInteger shift operations, and a LoopLimit bypass via range enumeration in builtin functions. Attackers capable of supplying templates can trigger out-of-memory exceptions or CPU exhaustion, which typically results in the termination of the entire host process.
Recommendations Update to version 7.0.0 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74785
GHSA-XW6W-9JJH-P9CR

Affected Products

Scriban