๐Ÿ” CVE Alert

CVE-2026-74784

UNKNOWN 0.0

Scriban before 7.2.0 Denial of Service via array.insert_at

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second.

CWE CWE-770
Vendor scriban
Product scriban
Published Aug 16, 2026
Stay Ahead of the Next One

Get instant alerts for scriban scriban

Be the first to know when new unknown vulnerabilities affecting scriban scriban are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

scriban / scriban
0 < 7.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/scriban/scriban/security/advisories/GHSA-24c8-4792-22hx vulncheck.com: https://www.vulncheck.com/advisories/scriban-before-denial-of-service-via-array-insert-at

Credits

๐Ÿ” fg0x0