HIGHVulnerability

CVE-2026-74794

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. Attackers can supply circular reference objects to the template context, exhausting stack space and triggering an uncatchable StackOverflowException that terminates the hosting process.

Properties

severity
HIGH
score
7.5
epss_score
0.00278
cve_id
CVE-2026-74794
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
published_at
2026-08-16T14:16:57.450
last_modified
2026-08-31T20:30:14.457
epss_percentile
0.19938

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Uncontrolled Recursion

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-74794 — Ninja Signal Threat Intelligence | Ninja Signal