CVE-2026-74794: Scriban before 6.6.0 Denial of Service via Infinite Recursion
Published Aug 16, 2026
·Updated
Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the hosting process.
Affected Software
1 affected component
Scriban Scriban<6.6.0
Event History
Aug 16, 2026
CVE Published
via MITRE·01:14 PM
Data Sourced
via MITRE·01:14 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-74794?
CVE-2026-74794 has a high severity rating of 7.5.
2
How do I fix CVE-2026-74794?
To mitigate CVE-2026-74794, upgrade Scriban to version 6.6.0 or later to limit object recursion.
3
What type of vulnerability is CVE-2026-74794?
CVE-2026-74794 is a denial of service vulnerability caused by infinite recursion in Scriban.
4
What could happen if CVE-2026-74794 is exploited?
Exploitation of CVE-2026-74794 can lead to stack space exhaustion resulting in a StackOverflowException.
5
Which versions of Scriban are affected by CVE-2026-74794?
CVE-2026-74794 affects Scriban versions before 6.6.0.