What is CVE-2026-74787?
A vulnerability in Scriban template engine before version 7.0.0 involves uncontrolled recursion in the 'object.to_json' function due to missing depth limits and circular reference detection. Attackers can craft self-referencing objects to trigger a StackOverflowException, leading to Denial of Service (DoS). Immediate upgrade to Scriban 7.0.0 or later is strongly recommended.
Azərbaycanca: Scriban şablon mühərrikinin 7.0.0-dan əvvəlki versiyalarında 'object.to_json' funksiyasındakı nəzarətsiz rekursiya zəifliyidir. Hücumçular öz-özünə istinad edən obyektlərlə stack overflow yaradaraq xidmətə qarşı deaktivasiya hücumu (DoS) törədə bilərlər. Təcili olaraq Scriban kitabxanasını 7.0.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
In which Scriban function was the uncontrolled recursion vulnerability found?
The vulnerability was found in the 'object.to_json' function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.