Retour à la veille

CVE-2026-74784

Publié : 16 août 2026
Modifié : 16 août 2026
Lien officiel NVD

Description détaillée

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second.

Références et Patchs

Dernières Vulnérabilités