What is CVE-2026-73060?
CVE-2026-73060 is a denial of service vulnerability in Scriban versions 3.0.0 through 7.2.5, where the ScriptRange.Multiply operator bypasses LoopLimit with a lazy sequence left operand. Attackers can trigger billions of uncharged iterations using array multiplication on lazy sequences. Users should upgrade to the latest version.
Azərbaycanca: CVE-2026-73060, Scriban 3.0.0-dən 7.2.5-ə qədər versiyalarda ScriptRange.Multiply operatorunda denial of service zəifliyidir. Sol operand lazy sequence olduqda LoopLimit bypass olunaraq milyardlarla təkrarlanma icra olunur. Təsirə məruz qalmamaq üçün istifadəçilər Scriban-i ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which versions of Scriban are affected by CVE-2026-73060?
CVE-2026-73060 affects Scriban versions 3.0.0 through 7.2.5.
How can I protect against CVE-2026-73060?
Users should upgrade Scriban to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.