Impact
The vulnerability resides in the ID3v2 parser of the music-metadata library, where the declared tag size is accepted without validation before memory is allocated. A malicious file that contains only an ID3v2 header yet claims a massively large payload can compel the parser to reserve up to roughly 268 MiB of memory. Because the actual data stream terminates early, the read operation fails, the failure is silently handled, and the caller still receives a metadata object, while the application has consumed a significant portion of its available memory. This unchecked allocation can degrade or halt the host process, resulting in a denial of service. The weakness is classified as CWE‑789.
Affected Systems
The issue affects all versions of the Borewit:music-metadata library older than 11.16.0. Version 11.16.0 and later include the fix that validates the tag size prior to allocation.
Risk and Exploitability
The CVSS score of 6.2 indicates medium severity. EPSS data are unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the processing of media files that contain a crafted ID3v2 header; an application that imports or serves such files can be compelled to allocate large buffers, exhausting memory resources. Once memory is saturated, the application or system may become unresponsive or crash, depending on resource limits and process isolation. No known public exploit has been reported, but the risk of opportunistic exploitation remains due to the straightforward payload construction.
OpenCVE Enrichment
Github GHSA