Executive brief
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString
Affected products
- NuGet Scriban.Signed
- NuGet scriban
Junglewise Threat Intelligence
CVE-2026-74786 · Severity: low · CVSS 3.1 · Published 2026-03-24
Technologies: Scriban.Signed (NuGet), scriban (NuGet). Vendors: NuGet.
Scriban: Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString