---
id: CVE-2026-73060
title: >-
  Scriban versions from 3.0.0 through 7.2.5 contain a denial of service
  vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit
  when the left operand is a lazy sequence
summary: >-
  Scriban versions from 3.0.0 through 7.2.5 contain a denial of service
  vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit
  when the left operand is a lazy sequence. Attackers can supply templates with
  array multipli…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
vendor: scriban
product: scriban
affected:
  - scriban >= 3.0.0 <= 7.2.5
published: '2026-08-16'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T18:18:39.497'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-73060'
references:
  - url: >-
      https://github.com/scriban/scriban/commit/205ca6a7c2349d3d388bd5f1f7729ee198c0d5e5
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/scriban/scriban/commit/c3f03bfc912e14b306a01a03e611f606b05f9c33
    label: disclosure@vulncheck.com
  - url: 'https://github.com/scriban/scriban/security/advisories/GHSA-89cf-6hmv-8rxm'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/scriban-through-denial-of-service-via-scriptrange-multiply
    label: disclosure@vulncheck.com
  - url: 'https://github.com/scriban/scriban/security/advisories/GHSA-89cf-6hmv-8rxm'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.0067
epssPercentile: 0.50099
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-17T15:34:39.785414Z'
ingestedAt: '2026-09-30T18:17:24.555Z'
---

## Overview

Scriban versions from 3.0.0 through 7.2.5 contain a denial of service vulnerability in the ScriptRange.Multiply operator that bypasses LoopLimit when the left operand is a lazy sequence. Attackers can supply templates with array multiplication on lazy sequences to execute billions of uncharged iterations, pinning CPU cores and exhausting garbage collection resources even when LoopLimit is set to 1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
