CVE-2026-103087 Details
Description
Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.
A denial-of-service vulnerability has been identified in the Gosub browser engine, specifically in versions through 0.1.0 and the main branch prior to commit 46868b3. The issue arises from uncontrolled recursion when the engine processes SVG documents with a high number of deeply nested elements. This lack of a nesting depth limit allows remote attackers to craft SVG files that, when rendered, exhaust the application's thread stack, leading to a crash. The malicious SVG can be embedded in an HTML document using the IMG element's SRC attribute, requiring only that the victim visit the page.
Users can update to the main branch at commit 46868b3 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 30, 2026CISA-ADP
Assessed Sep 30, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/gosub-io/gosub-engine/security/advisories/GHSA-c762-mxfh-vwvp | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/gosub-io/gosub-engine/pull/1229 | [email protected] | Issue TrackingVendor |
| https://github.com/gosub-io/gosub-engine/security/advisories/GHSA-c762-mxfh-vwvp | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-674 | Uncontrolled Recursion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Gosub | <= 0.1.0 (semver) main before 46868b3 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 30, 2026 | CVE Modified | CISA-ADP |
| Sep 30, 2026 | New CVE Received | [email protected] |
Volerion