What is CVE-2026-74789?
CVE-2026-74789 is a vulnerability in the Scriban templating engine before version 7.0.0 (affected <= 6.6.0) where the 'LoopLimit' constraint is only applied to script loops, not to expensive iterations within built-in operators and functions. This allows a single expression to bypass resource limits, causing potential denial of service. Upgrading to Scriban 7.0.0 or later is strongly recommended.
Azərbaycanca: CVE-2026-74789, Scriban şablon mühərrikinin 7.0.0-dan əvvəlki versiyalarında (təsirlənən <= 6.6.0) aşkar edilmiş zəiflikdir. Bu boşluq 'LoopLimit' məhdudiyyətinin yalnız skript dövrələrinə tətbiq edilməsi, daxili operator və funksiyalar daxilindəki bahalı iterasiyaları məhdudlaşdırmaması səbəbindən yaranır. Təcili olaraq Scriban-ı 7.0.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: Scriban
FAQ2
Which versions of Scriban are affected by CVE-2026-74789?
The vulnerability affects versions of the Scriban templating engine prior to 7.0.0, specifically version 6.6.0 and below.
How can I protect my system from CVE-2026-74789?
It is strongly recommended to immediately upgrade Scriban to version 7.0.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.