天下漏洞,尽知其名
MEDIUM

CVE-2026-103087 Gosub 引擎 SVG 嵌套拒绝服务漏洞

影响远程攻击者可致浏览器引擎崩溃,造成拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

Gosub 浏览器引擎在处理 SVG 文档时未限制节点嵌套深度,存在不受控递归问题。攻击者可通过构造包含大量深层嵌套元素的 SVG 文档,使渲染线程栈溢出并导致应用崩溃。该恶意 SVG 可借助 IMG 元素的 SRC 属性嵌入,受害者仅需访问攻击者控制的网页即可触发。

影响范围

Gosub 引擎(gosub-engine)

漏洞详情

漏洞类型为不受控递归导致的栈耗尽(CWE-674)。成因是引擎在解析和渲染 SVG 节点时未对嵌套深度设置上限,深层递归调用不断消耗线程栈空间。利用方式为攻击者制作含过量深层嵌套元素的 SVG,并通过 IMG 标签的 SRC 属性加载,使受害者在浏览网页时触发崩溃。

利用条件与风险

利用前提是受害者访问攻击者控制的网页,无需其他交互或权限,实战中可被用于网页挂马式的拒绝服务攻击,但仅造成崩溃,暂未见代码执行或数据泄露风险。

修复建议

官方已在 commit 46868b3 中修复,建议升级至该提交之后的版本;暂无公开信息说明其他临时缓解措施,可考虑在渲染前限制 SVG 嵌套深度或禁用不可信来源的 SVG 加载。

原始情报

Uncontrolled recursion in the Gosub browser engine (gosub-engine) through 0.1.0 and main before commit 46868b3 allows a remote attacker to cause a Denial of Service (stack exhaustion and application crash) via an SVG document containing an excessive number of deeply nested elements. Because the engine does not limit the nesting depth of processed SVG nodes, rendering such a document overflows the thread stack and terminates the application. The malicious SVG can be embedded through the SRC attribute of an IMG element, and thus exploitation only requires the victim to visit an attacker-controlled web page.