HIGH 8.7 NVD
CVE-2026-74787
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference dete
Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.
References
- https://github.com/scriban/scriban/security/advisories/GHSA-xcx6-vp38-8hr5
- https://www.vulncheck.com/advisories/scriban-before-uncontrolled-recursion-via-object-to-j
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-08-16 via NVD.
vulnfeed aggregates 11848 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.