Impact
Uncontrolled recursion in the Gosub browser engine allows a remote attacker to cause a stack exhaustion and application crash by feeding a malicious SVG document with a deeply nested element hierarchy. The engine has no limit on SVG node nesting depth, so parsing such a document overflows the thread stack. The vulnerability is exposed when an SVG is embedded via the SRC attribute of an IMG element, meaning a victim only needs to visit an attacker‑controlled web page.
Affected Systems
The vulnerability affects the Gosub browser engine (gosub‑io:gosub‑engine) in all releases through version 0.1.0 and all commits on the main branch before commit 46868b3.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity threat. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation is remote and only requires the victim to load the malicious SVG by visiting a web page; no user interaction beyond normal page browsing is needed. An attacker can trigger the denial of service by causing the application to crash, which may impact availability for users of the affected engine.
OpenCVE Enrichment