CVE-2026-74785: Scriban

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in builtin functions. Attackers who can supply templates can cause out-of-memory exceptions or CPU exhaustion, typically terminating the entire host process.

Affected products

  • Scriban Scriban: before 7.0.0 (fixed in 7.0.0)

Published 2026-08-16. Last modified 2026-08-31.