Description
Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.
Published: 2026-09-30
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

Uncontrolled recursion in the Gosub browser engine allows a remote attacker to cause a stack exhaustion and application crash by feeding a malicious SVG document with a deeply nested element hierarchy. The engine has no limit on SVG node nesting depth, so parsing such a document overflows the thread stack. The vulnerability is exposed when an SVG is embedded via the SRC attribute of an IMG element, meaning a victim only needs to visit an attacker‑controlled web page.

Affected Systems

The vulnerability affects the Gosub browser engine (gosub‑io:gosub‑engine) in all releases through version 0.1.0 and all commits on the main branch before commit 46868b3.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity threat. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation is remote and only requires the victim to load the malicious SVG by visiting a web page; no user interaction beyond normal page browsing is needed. An attacker can trigger the denial of service by causing the application to crash, which may impact availability for users of the affected engine.

Generated by OpenCVE AI on September 30, 2026 at 07:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade gosub-engine to a version released after commit 46868b3 that implements a recursion depth limit.
  • If an upgrade is not immediately possible, block or sanitize SVG content in user‑provided documents, or restrict the SRC attribute of IMG elements from loading external SVGs.
  • Restart the application or employ a watchdog process to automatically recover after a crash caused by the vulnerability.

Generated by OpenCVE AI on September 30, 2026 at 07:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title Uncontrolled Recursion in Gosub Browser Engine Leads to Denial of Service

Wed, 30 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.
Weaknesses CWE-674
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-30T00:35:06.196Z

Reserved: 2026-09-30T00:35:05.437Z

Link: CVE-2026-103087

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T02:16:57.043

Modified: 2026-09-30T02:16:57.043

Link: CVE-2026-103087

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T07:45:18Z

Weaknesses