Infinite Recursion Vulnerability in Scriban by Scriban
CVE-2026-74794

8.7HIGH

Key Information:

Vendor

Scriban

Status
Vendor
CVE Published:
16 August 2026

What is CVE-2026-74794?

Scriban prior to version 6.6.0 is susceptible to an infinite recursion vulnerability due to the default setting of the ObjectRecursionLimit property being unlimited. This flaw allows attackers to introduce circular reference objects into the template context. As a result, the application's stack space may be exhausted, leading to a StackOverflowException that can terminate the hosting process unexpectedly.

Affected Version(s)

scriban 0 < 6.6.0

scriban 6.6.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.