---
id: CVE-2026-74783
title: >-
  Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing
  ExpressionDepthLimit guard that fails to stop recursive descent parsing of
  deeply nested expressions
summary: >-
  Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing
  ExpressionDepthLimit guard that fails to stop recursive descent parsing of
  deeply nested expressions. Attackers can supply templates with deeply nested
  parentheses, array initi…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-674
vendor: scriban
product: scriban
affected:
  - scriban >= 6.6.0 <= 7.2.0
published: '2026-08-16'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:18:40.253'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-74783'
references:
  - url: 'https://github.com/scriban/scriban/security/advisories/GHSA-6q7j-xr26-3h2c'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/scriban-through-parser-recursion-denial-of-service
    label: disclosure@vulncheck.com
  - url: 'https://github.com/scriban/scriban/security/advisories/GHSA-6q7j-xr26-3h2c'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00488
epssPercentile: 0.39676
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-17T16:48:37.450838Z'
ingestedAt: '2026-09-30T18:17:24.554Z'
---

## Overview

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested expressions. Attackers can supply templates with deeply nested parentheses, array initializers, object initializers, or unary operators to trigger an uncatchable StackOverflowException that immediately terminates the host process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
