Open Closed

Volo.Abp.Emailing Scriban Vulnerability (GHSA-grr9-747v-xvcp) - DoS Recursion in Email Templating #10543


User avatar
0
maziz101 created

Detected security warning in Scriban (transitive dep of Volo.Abp.Emailing). Infinite recursion on circular refs causes StackOverflow/DoS crash during object rendering in templates (e.g., Layout.tpl). โ€‹ Risky for email services with user-influenced data. Request:

  • Upgrade path/timeline for Scriban in next ABP release.
  • Config guidance for safe ObjectRecursionLimit.
  • Affected versions list.

Links:

  1. GitHub Advisory: https://github.com/scriban/scriban/security/advisories/GHSA-grr9-747v-xvcp
  2. OSV: https://github.com/ossf/osv.dev/blob/main/data/github/scriban/scriban/GHSA-grr9-747v-xvcp.json
  3. โ€‹Patch Commit: https://github.com/scriban/scriban/commit/a6fe6074199e5c04f4d29dc8d8e652b24d33e3e4

Prioritize for production security.


1 Answer(s)
  • User Avatar
    0
    maliming created
    Support Team Fullstack Developer

    hi

    Can you refer to: https://abp.io/support/questions/10541/SystemIdentityModelTokensJwt-6261-has-a-known-high-severity-vulnerability#answer-3a202f9f-4c50-529b-26b8-b28a076a4f77

    Thanks

Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with โค๏ธ on ABP v10.3.0-preview. Updated on March 13, 2026, 12:51
1
ABP Assistant
๐Ÿ” You need to be logged in to use the chatbot. Please log in first.