PT-2026-73161 · Scriban · Scriban
CVE-2026-74794
·
Published
2026-03-19
·
Updated
2026-08-16
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Scriban versions prior to 6.6.0
Description
An infinite recursion issue exists during object rendering when the
ObjectRecursionLimit property is set to unlimited. An attacker can provide objects with circular references to the template context, which exhausts stack space and triggers a StackOverflowException (a critical error occurring when the execution stack overflows), resulting in the termination of the hosting process.Recommendations
Update to version 6.6.0 or later.
As a temporary mitigation, configure the
ObjectRecursionLimit property to a limited value instead of unlimited.Exploit
Fix
DoS
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scriban