Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wcrg-p6mv-jx2j

Опубликовано: 16 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second.

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second.

EPSS

Процентиль: 18%
0.00263
Низкий

8.7 High

CVSS4

Дефекты

CWE-770

Связанные уязвимости

nvd
3 дня назад

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respecting LoopLimit or LimitToString constraints. Attackers can supply a large index parameter to trigger OutOfMemoryException and crash the host process in under a second.

EPSS

Процентиль: 18%
0.00263
Низкий

8.7 High

CVSS4

Дефекты

CWE-770