๐Ÿ” CVE Alert

CVE-2026-103087

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.

CWE CWE-674
Vendor gosub-io
Product gosub-engine
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for gosub-io gosub-engine

Be the first to know when new unknown vulnerabilities affecting gosub-io gosub-engine are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

gosub-io / gosub-engine
0 < 46868b3deae44544bee2a13e756772966dde950e

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/gosub-io/gosub-engine/security/advisories/GHSA-c762-mxfh-vwvp github.com: https://github.com/gosub-io/gosub-engine/pull/1229