← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 16, 2026 · 14:16via CVEFeed

CVE-2026-73060 - Scriban 3.0.0 through 7.2.5 Denial of Service via ScriptRange.Multiply

Brief

CVE ID : CVE-2026-73060

Published : Aug. 16, 2026, 2:16 p. m.

  • 6 hours, 50 minutes ago

Description : Scriban versions from 3.

  • 0 through 7.
  • 5 contain a denial of service vulnerability in the ScriptRange. Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on lazy sequences to execute billions of uncharged iterations, pinning CPU cores and exhausting garbage collection resources even when LoopLimit is set to 1.

Severity: 7.5

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed