CVE-2026-103087
Last modified
CVE-2026-103087 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application.
Description
Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| gosub-io | gosub-engine | < 46868b3deae44544bee2a13e756772966dde950e |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-103087?
How severe is CVE-2026-103087?
How do I fix CVE-2026-103087?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-103057AiSOC versions 5.1.0 before 12.0.0 contain an authentication…4.3
- CVE-2026-103063Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-103064Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-103067Cross-Site Request Forgery (CSRF) vulnerability in Memberful…8
- CVE-2026-103068Subscriber Privilege Escalation in ByteCoreStack – MCP…8.8
- CVE-2026-103082Server-Side Request Forgery (SSRF) vulnerability in LA-Studi…7.2
- CVE-2026-103088Handlebars.java before 4.5.5 allows directory traversal. In …7.5
- CVE-2026-103099Pexip Infinity before 41.1 is affected by improper input val…7.5
- CVE-2026-1031IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2…6.1
- CVE-2026-103100Pexip Infinity before 40.1 is affected by improper input val…7.5
- CVE-2026-103101Pexip Infinity 30.0 through 40.x before 41.0 is affected by …8.6
- CVE-2026-103102Pexip Infinity before 41.0 is affected by improper input val…8.6
Are you affected by CVE-2026-103087?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
