CVE-2026-74785

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in builtin functions. Attackers who can supply templates can cause out-of-memory exceptions or CPU exhaustion, typically terminating the entire host process.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-16 14:16

Updated : 2026-08-31 20:30


NVD link : CVE-2026-74785

Mitre link : CVE-2026-74785

CVE.ORG link : CVE-2026-74785


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption