Description
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the APEv2 parser reads an attacker-controlled tag-item size and allocates a Uint8Array for a binary item before proving that the declared item fits in the remaining tag or file data. A small crafted APE file can therefore trigger a disproportionate allocation, including through cover-art items, and repeated or concurrent parsing can exhaust process memory. The demonstrated impact is availability loss only. This issue is fixed in version 11.16.0.
Published: 2026-10-08
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

In music-metadata’s APEv2 parser, an attacker‑controlled tag‑item size is read before confirming that the item fits within the remaining tag or file data. This oversight allows a disproportionately large Uint8Array to be allocated, leading to memory exhaustion and application crashes. The vulnerability manifests only as availability loss and is classified as CWE‑789, uncontrolled memory allocation.

Affected Systems

Any use of Borewit’s music-metadata library prior to version 11.16.0 is affected. The fix applied in v11.16.0 verifies tag sizes before allocation, eliminating the dangerous memory growth. Systems that parse user‑supplied or third‑party media files with this library—such as Node.js applications or media players—must review their dependency versions.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity. EPSS data is not available, and the issue is not listed in CISA KEV. An attacker can exploit the flaw simply by providing a crafted APE file containing oversized tag items; no additional privileges or code execution are required. Successful exploitation leads to total application interruption through memory exhaustion, but it does not impact confidentiality or integrity.

Generated by OpenCVE AI on October 8, 2026 at 20:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade music‑metadata to version 11.16.0 or later to apply the tag‑size validation fix.
  • Verify that only trusted media files are parsed; reject or sanitize untrusted files before invoking the library.
  • Run the parsing routine in a sandboxed or memory‑restricted environment and monitor for abnormal memory consumption.
  • If immediate upgrade is not possible, disable APE tag processing or strip cover‑art extraction from the application logic.

Generated by OpenCVE AI on October 8, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-53v6-4h7p-p4gj music-metadata: Uncontrolled memory allocation in APEv2 parser
History

Thu, 08 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Borewit
Borewit music-metadata
Vendors & Products Borewit
Borewit music-metadata

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the APEv2 parser reads an attacker-controlled tag-item size and allocates a Uint8Array for a binary item before proving that the declared item fits in the remaining tag or file data. A small crafted APE file can therefore trigger a disproportionate allocation, including through cover-art items, and repeated or concurrent parsing can exhaust process memory. The demonstrated impact is availability loss only. This issue is fixed in version 11.16.0.
Title music-metadata: Uncontrolled memory allocation in APEv2 parser
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Borewit Music-metadata
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T19:32:13.101Z

Reserved: 2026-10-07T21:07:54.988Z

Link: CVE-2026-107387

cve-icon Vulnrichment

Updated: 2026-10-08T19:32:09.095Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:17:01.517

Modified: 2026-10-08T20:46:35.260

Link: CVE-2026-107387

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:30:18Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value