Denial of Service Vulnerability in Gosub Browser Engine by Gosub.io
CVE-2026-103087

7.1HIGH

Key Information:

Vendor

Gosub-io

Vendor
CVE Published:
30 September 2026

What is CVE-2026-103087?

A vulnerability in the Gosub browser engine allows remote attackers to exploit uncontrolled recursion through SVG documents. By using SVG files with an excessive amount of deeply nested elements, an attacker can induce stack exhaustion, leading to application crashes. This exploitation occurs when the affected engine processes such SVGs via the SRC attribute of IMG elements. Users are at risk of such attacks when visiting compromised web pages.

Affected Version(s)

gosub-engine 0 < 46868b3deae44544bee2a13e756772966dde950e

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.