ended3월 20일· 1 sources
GHSA-GRR9-747V-XVCP: GHSA-GRR9-747V-XVCP: Uncontrolled Recursion in Scriban Templates Leads to Denial of Service
Scriban 템플릿의 비제어 재귀로 인한 서비스 거부(DoS) 취약점 (GHSA-GRR9-747V-XVCP)
Why it matters
Scriban, a .NET text templating engine, has a high-severity DoS vulnerability (CVSS 7.5) caused by uncontrolled recursion during template parsing and object rendering. Maliciously crafted templates or circular object references can trigger an uncatchable StackOverflowException, crashing the host process. Mitigation involves upgrading to the patched package or manually setting ObjectRecursionLimit and ExpressionDepthLimit.
1
Sources
+0
24h
—
Growth
177d
Active
ScribanStackOverflowExceptionDoSCWE-674.NETNuGet