PT-2026-102971 · Unknown · Gosub-Engine

·

CVE-2026-103087

·

Published

2026-09-30

·

Updated

2026-09-30

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions gosub-engine versions 0.1.0 and earlier gosub-engine main branch before commit 46868b3
Description Uncontrolled recursion in the browser engine occurs when processing SVG documents with an excessive number of deeply nested elements. Since the engine does not limit the nesting depth of processed SVG nodes, rendering such a document leads to stack exhaustion and an application crash, resulting in a Denial of Service. This can be triggered when a malicious SVG is embedded via the SRC attribute of an IMG element, requiring only that a user visits a compromised web page.
Recommendations Update gosub-engine to a version later than 0.1.0. Update gosub-engine main branch to commit 46868b3 or later.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103087
GHSA-C762-MXFH-VWVP

Affected Products

Gosub-Engine