Junglewise Threat Intelligence

CVE-2026-74786: Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString

CVE-2026-74786 · Severity: low · CVSS 3.1 · Published 2026-03-24

Technologies: Scriban.Signed (NuGet), scriban (NuGet). Vendors: NuGet.

Executive brief

Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString

Affected products

  • NuGet Scriban.Signed
  • NuGet scriban

Related threats