Open Closed

Volo.Abp.Emailing Scriban Vulnerability (GHSA-grr9-747v-xvcp) - DoS Recursion in Email Templating #10543


User avatar
0
maziz101 created

Detected security warning in Scriban (transitive dep of Volo.Abp.Emailing). Infinite recursion on circular refs causes StackOverflow/DoS crash during object rendering in templates (e.g., Layout.tpl). โ€‹ Risky for email services with user-influenced data. Request:

  • Upgrade path/timeline for Scriban in next ABP release.
  • Config guidance for safe ObjectRecursionLimit.
  • Affected versions list.

Links:

  1. GitHub Advisory: https://github.com/scriban/scriban/security/advisories/GHSA-grr9-747v-xvcp
  2. OSV: https://github.com/ossf/osv.dev/blob/main/data/github/scriban/scriban/GHSA-grr9-747v-xvcp.json
  3. โ€‹Patch Commit: https://github.com/scriban/scriban/commit/a6fe6074199e5c04f4d29dc8d8e652b24d33e3e4

Prioritize for production security.

Markdown supported.
Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)

1 Answer(s)
  • User Avatar
    0
    maliming created
    Support Team Fullstack Developer

    hi

    Can you refer to: https://abp.io/support/questions/10541/SystemIdentityModelTokensJwt-6261-has-a-known-high-severity-vulnerability#answer-3a202f9f-4c50-529b-26b8-b28a076a4f77

    Thanks

    Markdown supported.
    Copy, paste, or drag & drop images and files (max 100 MB per file, 100 MB total per post)
Boost Your Development
ABP Live Training
Packages
See Trainings
Mastering ABP Framework Book
The Official Guide
Mastering
ABP Framework
Learn More
Mastering ABP Framework Book
Made with โค๏ธ on ABP v10.8.0-preview. Updated on September 28, 2026, 11:44
1
ABP Assistant
๐Ÿ” You need to be logged in to use the chatbot. Please log in first.