CVE-2026-74784: Scriban
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second.
Affected products
- Scriban Scriban: before 7.2.0 (fixed in 7.2.0)
Published 2026-08-16. Last modified 2026-08-31.