What is CVE-2026-74795?
CVE-2026-74795: An uncontrolled recursion vulnerability exists in Scriban's recursive-descent parser before version 6.6.0. It allows an attacker to cause denial of service via crafted template input by exploiting the lack of a default expression depth limit. Users should upgrade to version 6.6.0 or later immediately.
Azərbaycanca: CVE-2026-74795: Scriban şablon proqramında rekursiv analizatorda nəzarətsiz rekursiya zəifliyi aşkarlanıb. 6.6.0 versiyasından əvvəlki versiyalara təsir edir; təcavüzkar xüsusi hazırlanmış şablonla xidmət imtinası yarada bilər. İstifadəçilər dərhal 6.6.0 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of Scriban are affected by CVE-2026-74795?
This vulnerability affects all versions of Scriban prior to 6.6.0.
How can users protect themselves from CVE-2026-74795?
Users should immediately upgrade to Scriban version 6.6.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.