PT-2026-73157 · Scriban · Scriban

·

CVE-2026-74789

·

Published

2026-03-24

·

Updated

2026-08-17

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Scriban versions prior to 7.0.0
Description The software fails to apply the LoopLimit constraint to expensive iterations performed within built-in operators and functions, applying it only to script loop statements. This allows a single expression to cause excessive CPU or memory consumption, leading to a denial of service. This occurs in applications that render templates controlled by an attacker and rely on LoopLimit for safe execution.
Recommendations Update to version 7.0.0 or later.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-74789
GHSA-C875-H985-HVRC

Affected Products

Scriban