Junglewise Threat Intelligence

CVE-2026-74788: Scriban uncontrolled memory allocation in string.pad_left and string.pad_right

CVE-2026-74788 · Severity: high · CVSS 7.5 · Published 2026-08-16

Technologies: Scriban.Signed (NuGet), Scriban. Vendors: NuGet.

Executive brief

Scriban is a template engine used to render dynamic content in .NET applications. When exposed to untrusted templates, the string.pad_left and string.pad_right functions fail to validate the width parameter, allowing an attacker to trigger massive memory allocations (up to ~1GB per request) and crash the service via OutOfMemoryException. This affects the official Scriban playground on Azure and any application using Scriban with user-supplied templates.

Technical details

The vulnerability is an uncontrolled resource allocation (CWE-770) in the StringFunctions.PadLeft and StringFunctions.PadRight functions, which directly delegate to .NET's String.PadLeft/PadRight without bounds checking on the width parameter. An attacker can supply an arbitrarily large width value (e.g., 500,000,000) to trigger memory exhaustion before template rendering completes. The existing TemplateContext.LimitToString mitigation is ineffective because it only enforces the limit during ObjectToString() conversion—after the string has already been fully allocated in memory. Attack requires only network access and no authentication; a 39-byte POST request can consume ~1GB of memory. Scriban 7.0.0 patched this by adding width validation to both functions.

Affected products

  • Scriban Scriban <= 6.6.0

Timeline

  • 2026-03-22: disclosed: GHSA-v66j-x4hw-fv9g published on GitHub
  • 2026-08-16: advisory: CVE-2026-74788 published on NVD
  • 2026: patched: Scriban 7.0.0 released with fix

References

Related threats