Junglewise Threat Intelligence

Scriban unbounded string generation denial of service

Severity: medium · CVSS 5.3 · Published 2026-03-19

Technologies: Scriban, Scriban.Signed. Vendors: NuGet.

Executive brief

Scriban is a fast and powerful text templating engine for .NET. A vulnerability exists where an attacker can provide a specially crafted template that causes the application to consume massive amounts of memory, leading to a system crash or service outage. This occurs because the engine does not limit the size of strings generated during template processing by default.

Technical details

The Scriban templating engine is vulnerable to a Denial of Service (DoS) via memory exhaustion (CWE-770). The root cause is that `TemplateContext.LimitToString` defaults to `0` (unlimited), allowing for unbounded string concatenation. An attacker can craft a template with a loop that performs exponential string growth (e.g., doubling a string 30 times to reach ~1GB). While Scriban has a default `LoopLimit` of 1000, this does not prevent memory exhaustion from string operations within those loops. This can be exploited by any user capable of providing or influencing a template that is rendered by the server. The vulnerability is addressed in version 6.6.0 by enforcing a default string limit.

Affected products

  • Scriban Scriban <= 6.5.8
  • Scriban Scriban.Signed <= 6.5.8

Timeline

  • 2026-03-19: advisory: GitHub Advisory GHSA-5rpf-x9jg-8j5p published
  • 2026-03-19: patched: Fix committed to repository

References

Related threats