CVE-2026-74784
Scriban before 7.2.0 Denial of Service via array.insert_at
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second.
| CWE | CWE-770 |
| Vendor | scriban |
| Product | scriban |
| Published | Aug 16, 2026 |
Stay Ahead of the Next One
Get instant alerts for scriban scriban
Be the first to know when new unknown vulnerabilities affecting scriban scriban are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
scriban / scriban
0 < 7.2.0
References
Credits
๐ fg0x0