Resource Consumption Vulnerability in libmodplug by Konstanty Bialkowski
CVE-2026-108577
5.3MEDIUM
What is CVE-2026-108577?
A vulnerability exists in the ABC Music Format Parser within the libmodplug library up to version 0.8.9.1 that can lead to excessive resource consumption. This issue is triggered by the abc_add_gchord function found in src/load_abc.cpp, allowing an attacker to initiate a remote exploit that may degrade system performance or availability. Despite early notification, the vendor did not provide a timely response to address this concern.
Affected Version(s)
libmodplug 0.8.9.0
libmodplug 0.8.9.1
