What is CVE-2026-74784?
Scriban versions before 7.2.0 contain a denial of service vulnerability in the `array.insert_at` function, allowing attackers to trigger unbounded memory allocation (OutOfMemoryException) and crash the host process via a large index parameter. Users should upgrade to Scriban 7.2.0 or later immediately.
Azərbaycanca: Scriban <7.2.0 versiyalarında `array.insert_at` funksiyasında xidmət əngəli (DoS) zəifliyi aşkar edilib. Təcavüzkarlar böyük indeks parametri göndərərək nəzarətsiz yaddaş istehlakı (OutOfMemoryException) yaradıb prosesi çökdürə bilərlər. Tərtibatçılar dərhal Scriban 7.2.0 və ya daha yeni versiyaya yeniləmə etməlidirlər.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Scriban
FAQ2
In which Scriban function was the CVE-2026-74784 vulnerability discovered?
This vulnerability was discovered in Scriban's `array.insert_at` function, where attackers can trigger unbounded memory allocation by sending a large index parameter.
What action should users take to mitigate the CVE-2026-74784 vulnerability?
Users should immediately upgrade to Scriban 7.2.0 or a later version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.