Denial of Service Vulnerability in Scriban by Scriban
CVE-2026-73060
8.7HIGH
What is CVE-2026-73060?
Scriban versions from 3.0.0 to 7.2.5 are vulnerable to a denial of service attack via the ScriptRange.Multiply operator, which allows attackers to bypass the LoopLimit setting. This occurs when the left operand is a lazy sequence, permitting an attacker to craft templates that initiate extensive array multiplication. As a result, this could lead to massive CPU resource consumption and inefficient garbage collection handling, ultimately causing system performance degradation.
Affected Version(s)
scriban 0
