CVE-2026-74784: Scriban

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second.

Affected products

  • Scriban Scriban: before 7.2.0 (fixed in 7.2.0)

Published 2026-08-16. Last modified 2026-08-31.