PT-2026-73147 · Scriban · Scriban
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Scriban versions 3.0.0 through 7.2.5
Description
A denial of service issue exists in the
ScriptRange.Multiply operator. When the left operand is a lazy sequence, the LoopLimit is bypassed, allowing attackers to provide templates with array multiplication on lazy sequences. This can result in billions of uncharged iterations, which pins CPU cores and exhausts garbage collection resources, even if LoopLimit is configured to 1.Recommendations
Update Scriban to a version later than 7.2.5.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scriban