Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Scriban
Scriban scriban |
|
| Vendors & Products |
Scriban
Scriban scriban |
Sun, 16 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process. | |
| Title | Scriban before 7.0.0 Uncontrolled Recursion via object.to_json | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T14:07:14.547Z
Reserved: 2026-08-16T12:56:02.577Z
Link: CVE-2026-74787
Updated: 2026-08-18T14:06:59.869Z
Status : Received
Published: 2026-08-16T14:16:56.653
Modified: 2026-08-18T15:17:09.963
Link: CVE-2026-74787
No data.
OpenCVE Enrichment
Updated: 2026-08-17T10:58:40Z