Executive brief
Scriban, a text templating library for .NET, is vulnerable to a denial-of-service attack that can crash the entire application process. By providing a specially crafted template with deeply nested structures, an attacker can exhaust the system's memory stack, leading to an unrecoverable crash. This affects any application that allows users to provide or influence the templates being processed, such as web applications or reporting tools.
Technical details
Scriban utilizes a recursive-descent parser to process template expressions. The vulnerability (CWE-674) exists because the `ExpressionDepthLimit` property in `ParserOptions` defaults to `null` (disabled), allowing for unlimited recursion depth. An attacker can supply a template containing thousands of nested parentheses or blocks, which consumes thread stack space until a `StackOverflowException` is triggered. In the .NET runtime, this exception cannot be caught by standard `try-catch` blocks, resulting in the immediate termination of the hosting process. The issue is resolved in version 6.6.0 by introducing a default limit for expression depth.
Affected products
- scriban scriban <= 6.5.8
- scriban Scriban.Signed <= 6.5.8
Timeline
- 2026-03-19: disclosed
- 2026-03-19: advisory
- 2026-03-19: patched: Fixed in version 6.6.0