Junglewise Threat Intelligence

Scriban uncontrolled recursion in parser leads to Denial of Service

Severity: high · CVSS 7.5 · Published 2026-03-19

Technologies: Scriban, Scriban.Signed. Vendors: NuGet.

Executive brief

Scriban, a text templating library for .NET, is vulnerable to a denial-of-service attack that can crash the entire application process. By providing a specially crafted template with deeply nested structures, an attacker can exhaust the system's memory stack, leading to an unrecoverable crash. This affects any application that allows users to provide or influence the templates being processed, such as web applications or reporting tools.

Technical details

Scriban utilizes a recursive-descent parser to process template expressions. The vulnerability (CWE-674) exists because the `ExpressionDepthLimit` property in `ParserOptions` defaults to `null` (disabled), allowing for unlimited recursion depth. An attacker can supply a template containing thousands of nested parentheses or blocks, which consumes thread stack space until a `StackOverflowException` is triggered. In the .NET runtime, this exception cannot be caught by standard `try-catch` blocks, resulting in the immediate termination of the hosting process. The issue is resolved in version 6.6.0 by introducing a default limit for expression depth.

Affected products

  • scriban scriban <= 6.5.8
  • scriban Scriban.Signed <= 6.5.8

Timeline

  • 2026-03-19: disclosed
  • 2026-03-19: advisory
  • 2026-03-19: patched: Fixed in version 6.6.0

References

Related threats