Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 16 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second. | |
| Title | Scriban before 7.2.0 Denial of Service via array.insert_at | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-16T13:14:10.514Z
Reserved: 2026-08-16T12:56:02.577Z
Link: CVE-2026-74784
No data.
Status : Received
Published: 2026-08-16T14:16:56.263
Modified: 2026-08-16T14:16:56.263
Link: CVE-2026-74784
No data.
OpenCVE Enrichment
No data.