CVE-2026-74789: Scriban
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | array.size }} — or a memory-amplification expression such as {{ 'A' * 200000000 }} — can force large CPU or memory consumption even when LoopLimit is configured to a very small value, resulting in denial of service. Applications that render attacker-controlled templates and rely on LoopLimit for safe execution are affected.
Affected products
- Scriban Scriban: before 7.0.0 (fixed in 7.0.0)
Published 2026-08-16. Last modified 2026-08-31.