What is CVE-2026-74785?
Scriban template engine before version 7.0.0 contains three denial-of-service vulnerabilities in expression evaluation that bypass safety controls. These include unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in built-in functions. Users should upgrade to version 7.0.0 immediately.
Azərbaycanca: Scriban template mühərrikinin 7.0.0-dən əvvəlki versiyalarında ifadə qiymətləndirmədə üç ayrı xidmət dayandırma (DoS) zəifliyi aşkar edilib. Bu, təhlükəsizlik nəzarətlərini keçərək limitsiz string vurma, nəzarətsiz BigInteger sürüşdürmə əməliyyatları və daxili funksiyalarda dövr limitinin yan keçməsi vasitəsilə həyata keçirilir. İstifadəçilər dərhal 7.0.0 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of Scriban template engine are affected by CVE-2026-74785?
All versions of Scriban before 7.0.0 are affected by this vulnerability.
What should users do regarding CVE-2026-74785?
Users should immediately upgrade Scriban to version 7.0.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.