CVE-2026-73062: Scriban
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enforcing LoopLimit or overflow-safe arithmetic checks. Attackers can supply a large integer multiplier in a template to force multi-gigabyte memory allocations, causing resource exhaustion and availability degradation.
Affected products
- Scriban Scriban: from 3.0.0, up to and including 7.2.0
Published 2026-08-16. Last modified 2026-10-08.