← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 16, 2026 · 14:16via CVEFeed

CVE-2026-74785 - Scriban before 7.0.0 Denial of Service via Unbounded Resource Consumption

Brief

CVE ID : CVE-2026-74785

Published : Aug. 16, 2026, 2:16 p. m.

  • 6 hours, 50 minutes ago

Description : Scriban before 7.

  • 0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in builtin functions.

Attackers who can supply templates can cause out-of-memory exceptions or CPU exhaustion, typically terminating the entire host process.

Severity: 6.5

  • MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed