CVE-2026-74788Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functions, which perform no validation on the width parameter before delegating to .NET's String.PadLeft/PadRight. When an application exposes Scriban to untrusted template input, an attacker can supply an arbitrarily large width value (e.g., 500,000,000) to trigger ~1GB memory allocations in a single call, resulting in OutOfMemoryException and denial of service. The TemplateContext.LimitToString limit does not prevent this because it is only enforced after the string has been fully allocated.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-16: 3Patch / Workaround · 2026-08-16: 1Technical Details · 2026-08-16: 308-16
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-74788 - DoS in Scriban templates via string.pad_left/right. Unvalidated width triggers ~1GB allocations, OOM. CVSS 7.5. Unpatched. Update to 7.0.0 or restrict template access. #CVE #infosec #Scriban https://www.valtersit.com/cve/CVE-2026-74788 #CVE #infosec #SysAdmin #cybersecurity #Linux #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta #mexico

    Post summary

    The post identifies a DoS vulnerability in Scriban templates and recommends patching to version 7.0.0 or restricting template access.

    0000071
    1.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-74788 Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functi… https://www.cve.org/CVERecord?id=CVE-2026-74788 ----- Traducción: CVE-2026-74788 Scr… https://infoflow.cloud`

    Post summary

    A tweet announces CVE‑2026‑74788 for Scriban, highlighting an uncontrolled memory allocation in the pad_left/right template functions for versions <=6.6.0, and links to the CVE record.

    0000030
    99 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-74788 Scriban before 7.0.0 (affected versions &lt;= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_right template functi… https://www.cve.org/CVERecord?id=CVE-2026-74788

    Post summary

    This notice announces that Scriban versions up to 6.6.0 contain an uncontrolled memory allocation flaw tied to the string.pad_left and string.pad_right template functions.

    000001.2K
    58.0K followersView on X

Explore more