Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

scriban — Vulnerabilities & Security Advisories 15

Browse all 15 CVE security advisories affecting scriban. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates security vulnerability information for the Scriban template engine, categorized under various weakness classes and tagged for easy navigation. The content covers a wide range of security issues, including injection flaws, buffer overflows, and denial of service risks, spanning advisory data from the initial release through recent patches. By centralizing these records, the page allows security researchers and developers to track the vendor's response history and understand how specific weakness classes affect this particular library. Visitors can discover detailed descriptions of past incidents, analyze the progression of remediation efforts, and look up the product's vulnerability history to assess its current security posture. This resource does not provide real-time alerts or predictive analytics but serves as a static reference for historical data and documented flaws. Users interested in the safety of their .NET applications should review these findings to ensure their implementations do not rely on unpatched versions. The aggregation process ensures that advisories from multiple sources are correlated and presented in a unified format, reducing the effort required to research the vendor independently. This approach supports transparency and helps stakeholders make informed decisions about dependency management and update schedules within their software development lifecycles.

Found 15 results / 15Clear Filters
Top products by scriban: scriban
HighGHSA-wgh7-7m3c-h252026-08-16
Stack Overflow via nested array initializers bypasses ExpressionDepthLimit fix · Advisory · scriban/scriban · GitHub
High2026-08-16
Multiple Denial-of-Service Vectors via Unbounded Resource Consumption in Scriban Expression Evaluation · Advisory · scri
High2026-08-16
Uncontrolled Memory Allocation via string.pad_left/pad_right Allows Remote Denial of Service · Advisory · scriban/scriba
High2026-08-16
array * int (ScriptArray<T>.TryEvaluate) bypasses LoopLimit — incomplete fix for GHSA-c875-h985-hvrc, missed sibling of
MediumGHSA-wgh7-7m3c-fx252026-08-16
ExpressionDepthLimit guard is non-enforcing — parser-recursion DoS in 6.6.0–7.2.0 (incomplete fix for GHSA-wgh7-7m3c-fx2
High2026-08-16
array.insert_at index parameter DoS bypasses LoopLimit and LimitToString · Advisory · scriban/scriban · GitHub
Critical2026-08-16
Stale include cache survives TemplateContext.Reset() leading to authorization bypass · Advisory · scriban/scriban · GitH
High2026-08-16
TypedObjectAccessor cache bypasses MemberFilter after TemplateContext reuse, leading to sandbox escape · Advisory · scri
Medium2026-08-16
Denial of Service via Unbounded Cumulative Template Output Bypassing LimitToString · Advisory · scriban/scriban · GitHub
High2026-08-16
Uncontrolled Recursion in Parser Leads to Stack Overflow and Process Crash (Denial of Service) · Advisory · scriban/scri
High2026-08-16
Uncontrolled Recursion in `object.to_json` Causes Unrecoverable Process Crash via StackOverflowException · Advisory · sc
High2026-08-16
Infinite Recursion during Object Rendering Leads to Stack Overflow and Process Crash (Denial of Service) · Advisory · sc
High2026-08-16
Built-in operations bypass LoopLimit and delay cancellation, enabling denial-of-service · Advisory · scriban/scriban · G
MediumGHSA-7jvp-hj45-2f2m2026-08-16
Template Writes to Arbitrary CLR Properties via `TypedObjectAccessor` (Mass Assignment + `private` / `init` / `internal`
Medium2026-08-16
Limit array multiplication growth · scriban/scriban@205ca6a · GitHub
High2026-08-16
Fix missing tests · scriban/scriban@c3f03bf · GitHub
HighGHSA-q6rr-fm2g-g5x82026-08-16
array * int on a lazy sequence (ScriptRange.Multiply) bypasses LoopLimit — incomplete fix for GHSA-q6rr-fm2g-g5x8 · Advi

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with scriban. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.