Tag
critical
advisory
Access-Modifier Bypass in Scriban
3 TTPs 1 CVEScriban versions prior to 7.2.2 contain an access-modifier bypass in TypedObjectAccessor that allows unauthorized modification of private, internal, or init-only CLR object properties via template injection.
Scriban +3
vulnerability
dot-net
template-injection
access-control
sandbox-bypass
cve-2026-74790
.net
denial-of-service
+1
3t
1c
medium
advisory
Datadog dd-trace-dotnet Improper W3C Baggage Header Parsing Leads to DoS
1 TTPA Denial of Service (DoS) vulnerability exists in Datadog tracing libraries (`dd-trace-dotnet`) due to improper parsing of W3C baggage HTTP headers, allowing remote, unauthenticated attackers to send requests with arbitrarily large baggage headers, causing unbounded CPU and memory consumption and leading to service unavailability for any HTTP service instrumented with affected library versions where baggage propagation is enabled by default. The issue, tracked as CVE-2026-50273, is resolved in version 3.43.0 and later.
Datadog.Trace +1
denial-of-service
vulnerability
dot-net
1t