What is CVE-2026-74794?
Scriban before 6.6.0 has an infinite recursion vulnerability due to the ObjectRecursionLimit defaulting to unlimited. Attackers can supply circular reference objects to the template context, causing an uncatchable StackOverflowException and exhausting stack space. Affected users should upgrade to version 6.6.0 immediately.
Azərbaycanca: Scriban 6.6.0-dən əvvəlki versiyalarda, həddi təyin olunmayan ObjectRecursionLimit səbəbindən sonsuz rekursiya zəifliyi mövcuddur. Təcavüzkar şablon kontekstinə dairəvi istinad obyektləri göndərərək StackOverflowException yaradıb sistemi çökdürə bilər. Təsirlənən istifadəçilər dərhal 6.6.0 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of Scriban are affected by CVE-2026-74794?
All versions of Scriban before 6.6.0 are affected by this vulnerability.
What should users do to protect against CVE-2026-74794?
Users should upgrade to version 6.6.0 of Scriban immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.