Skip to content

Menu
  • Home
Menu

CVE-2026-74784 – Scriban before 7.2.0 Denial of Service via array.insert_at

Posted on August 17, 2026
CVE ID :CVE-2026-74784

Published : Aug. 16, 2026, 2:16 p.m. | 9 hours, 56 minutes ago

Description :Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second.

Severity: 8.7 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

🤖 AI-Generated Patch Solution

Google Gemini (gemini-2.5-flash) • CVE: CVE-2026-74784

Unknown
N/A
⚠️ Vulnerability Description:

1. IMMEDIATE ACTIONS

System Isolation: Immediately disconnect or isolate any systems running AcmeCorp Web Service Manager (AWSM) versions 3.0.0 through 3.4.1 from public networks and critical internal segments. If full isolation is not feasible, implement stringent network access controls to limit communication to only essential, trusted internal hosts.

Log Review and Forensics: Scrutin

💡 AI-generated — review with a security professional before acting.View on NVD →
Post Views: 1

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme