CVE-2026-74787Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular reference detection. Attackers can craft templates with self-referencing objects to trigger unbounded recursion, causing a StackOverflowException that fatally terminates the hosting .NET process.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-674

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-16: 3Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-16: 308-16
Signal classification1 categories
Disclosure
3100.0%
Referenced assets5 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-74787 Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the https://object.to_json builtin function that lacks depth limits and circular reference detection.… https://www.cve.org/CVERecord?id=CVE-2026-74787

    Post summary

    The text announces an uncontrolled recursion vulnerability in Scriban's object.to_json function and provides technical details, but offers no PoC, exploit, active exploitation evidence, or patch information.

    000011.1K
    58.0K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Disclosure

    CVE-2026-74787 - Uncontrolled recursion in Scriban's http://object.to_json. Crafted templates cause stack overflow, crashing .NET apps. CVSS 7.5. No patch yet - mitigate by limiting template input. #CVE #Scriban #infosec https://www.valtersit.com/cve/CVE-2026-74787/ #CVE #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico

    Post summary

    CVE-2026-74787 details an uncontrolled recursion in Scriban's http://object.to_json that triggers stack overflows in .NET applications (CVSS 7.5). No patch exists yet, but limiting template input mitigates the issue.

    0000053
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-74787 Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the https://object.to_json builtin function that lacks depth limits and circular reference detection.… https://www.cve.org/CVERecord?id=CVE-2026-74787 ----- Traducción: CVE-… https://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-74787, describing an uncontrolled recursion issue in Scriban's object.to_json function, but provides no PoC, exploitation detail, or mitigation information.

    0000039
    99 followersView on X

Explore more