Denial of Service Vulnerability in Scriban by Scriban Technologies
CVE-2026-74783
8.7HIGH
What is CVE-2026-74783?
Scriban versions 6.6.0 to 7.2.0 are vulnerable to a Denial of Service attack due to a misconfigured ExpressionDepthLimit. This issue allows attackers to craft templates with nested structures that can trigger a StackOverflowException, causing the host process to terminate uncontrollably. This vulnerability can be exploited by providing specially designed templates featuring deeply nested parentheses and complex initializers, leading to severe service disruptions.
Affected Version(s)
scriban 0
