Resource Consumption Vulnerability in libmodplug by Konstanty Bialkowski
CVE-2026-108577

5.3MEDIUM

Key Information:

Vendor
CVE Published:
11 October 2026

What is CVE-2026-108577?

A vulnerability exists in the ABC Music Format Parser within the libmodplug library up to version 0.8.9.1 that can lead to excessive resource consumption. This issue is triggered by the abc_add_gchord function found in src/load_abc.cpp, allowing an attacker to initiate a remote exploit that may degrade system performance or availability. Despite early notification, the vendor did not provide a timely response to address this concern.

Affected Version(s)

libmodplug 0.8.9.0

libmodplug 0.8.9.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

jenseny20 (VulDB User)
VulDB CNA Team
.