Denial of Service Vulnerability in Gosub Browser Engine by Gosub.io
CVE-2026-103087
7.1HIGH
What is CVE-2026-103087?
A vulnerability in the Gosub browser engine allows remote attackers to exploit uncontrolled recursion through SVG documents. By using SVG files with an excessive amount of deeply nested elements, an attacker can induce stack exhaustion, leading to application crashes. This exploitation occurs when the affected engine processes such SVGs via the SRC attribute of IMG elements. Users are at risk of such attacks when visiting compromised web pages.
Affected Version(s)
gosub-engine 0 < 46868b3deae44544bee2a13e756772966dde950e
