LOWVulnerability

CVE-2026-74784

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second.

Properties

epss_score
0.00263
cve_id
CVE-2026-74784
published_at
2026-08-16T14:16:56.263
last_modified
2026-08-31T20:30:14.457
epss_percentile
0.17827

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-74784 — Ninja Signal Threat Intelligence | Ninja Signal