Security Advisory

CVE-2026-74785

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-16 13:14:11
Last updated 2026-08-17 15:34:11
Assigner VulnCheck
CVSS score not scored
State PUBLISHED

Description

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through unbounded string multiplication, uncontrolled BigInteger shift operations, and LoopLimit bypass via range enumeration in builtin functions. Attackers who can supply templates can cause out-of-memory exceptions or CPU exhaustion, typically terminating the entire host process.