Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 16 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process. | |
| Title | Scriban before 7.0.0 Uncontrolled Recursion via object.to_json | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-16T13:14:12.485Z
Reserved: 2026-08-16T12:56:02.577Z
Link: CVE-2026-74787
No data.
Status : Received
Published: 2026-08-16T14:16:56.653
Modified: 2026-08-16T14:16:56.653
Link: CVE-2026-74787
No data.
OpenCVE Enrichment
Updated: 2026-08-16T15:15:04Z
-
CWE-674
Uncontrolled Recursion