CVE-2026-103087

Source
https://cve.org/CVERecord?id=CVE-2026-103087
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103087.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103087
Aliases
  • GHSA-c762-mxfh-vwvp
Published
2026-09-30T00:35:06Z
Modified
2026-10-08T02:50:59Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.

Database specific
{
    "cna_assigner": "mitre",
    "cwe_ids": [
        "CWE-674"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103087.json"
}
References

Affected packages

Git / github.com/gosub-io/gosub-engine

Affected ranges

Type
GIT
Repo
https://github.com/gosub-io/gosub-engine
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103087.json"