CVE-2026-74794

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the hosting process.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-16 14:16

Updated : 2026-08-31 20:30


NVD link : CVE-2026-74794

Mitre link : CVE-2026-74794

CVE.ORG link : CVE-2026-74794


JSON object : View

Products Affected

No product.

CWE
CWE-674

Uncontrolled Recursion