{"id":"CVE-2026-74789","aliases":["GHSA-c875-h985-hvrc"],"url":"https://o3.security/vulnerability/CVE-2026-74789","summary":"Scriban before 7.0.0 LoopLimit Bypass via Built-in Operations","details":"Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed inside built-in operators and functions. As a result, a single expression such as {{ 1..1000000 | array.size }} — or a memory-amplification expression such as {{ 'A' * 200000000 }} — can force large CPU or memory consumption even when LoopLimit is configured to a very small value, resulting in denial of service. Applications that render attacker-controlled templates and rely on LoopLimit for safe execution are affected.","published":"2026-08-16T13:14:13.792Z","modified":"2026-08-17T03:55:04.554490474Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"NuGet","name":"scriban","fixedVersion":"7.0.0"},{"ecosystem":"NuGet","name":"Scriban.Signed","fixedVersion":"7.0.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74789.json"},{"type":"ADVISORY","url":"https://github.com/scriban/scriban/security/advisories/GHSA-c875-h985-hvrc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74789"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/scriban-before-looplimit-bypass-via-built-in-operations"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T03:55:04.554490474Z"}}