← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 16, 2026 · 14:16via CVEFeed

CVE-2026-74783 - Scriban 6.6.0 through 7.2.0 Parser Recursion Denial of Service

Brief

CVE ID : CVE-2026-74783

Published : Aug. 16, 2026, 2:16 p. m.

  • 6 hours, 50 minutes ago

Description : Scriban versions 6.

  • 0 through 7.
  • 0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable StackOverflowException that immediately terminates the host process.

Severity: 7.5

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed