Description
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe tag-size field and allocates the complete tag body before checking whether the input contains the declared bytes. A truncated file containing only an ID3v2 header can request an allocation approaching 268 MiB; the allocation succeeds, the subsequent read reaches end of stream, the EndOfStreamError is caught internally, and the caller receives a normal metadata object. This issue is fixed in version 11.16.0.
Published: 2026-10-08
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Memory Exhaustion
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the ID3v2 parser of the music-metadata library, where the declared tag size is accepted without validation before memory is allocated. A malicious file that contains only an ID3v2 header yet claims a massively large payload can compel the parser to reserve up to roughly 268 MiB of memory. Because the actual data stream terminates early, the read operation fails, the failure is silently handled, and the caller still receives a metadata object, while the application has consumed a significant portion of its available memory. This unchecked allocation can degrade or halt the host process, resulting in a denial of service. The weakness is classified as CWE‑789.

Affected Systems

The issue affects all versions of the Borewit:music-metadata library older than 11.16.0. Version 11.16.0 and later include the fix that validates the tag size prior to allocation.

Risk and Exploitability

The CVSS score of 6.2 indicates medium severity. EPSS data are unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the processing of media files that contain a crafted ID3v2 header; an application that imports or serves such files can be compelled to allocate large buffers, exhausting memory resources. Once memory is saturated, the application or system may become unresponsive or crash, depending on resource limits and process isolation. No known public exploit has been reported, but the risk of opportunistic exploitation remains due to the straightforward payload construction.

Generated by OpenCVE AI on October 8, 2026 at 21:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Borewit:music-metadata package to version 11.16.0 or later, which includes validation of the tag-size field before allocation.
  • If an upgrade is not immediately possible, implement pre‑parse checks that reject or truncate ID3v2 headers whose declared size exceeds a safe threshold, such as 10 MiB.
  • Run the metadata parsing code in a sandboxed or resource‑limited environment, enforcing hard limits on memory allocation or process memory usage to prevent a single file from exhausting the system.

Generated by OpenCVE AI on October 8, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-jjpr-9cvf-cq55 music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS
History

Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Borewit
Borewit music-metadata
Vendors & Products Borewit
Borewit music-metadata

Thu, 08 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe tag-size field and allocates the complete tag body before checking whether the input contains the declared bytes. A truncated file containing only an ID3v2 header can request an allocation approaching 268 MiB; the allocation succeeds, the subsequent read reaches end of stream, the EndOfStreamError is caught internally, and the caller receives a normal metadata object. This issue is fixed in version 11.16.0.
Title music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Borewit Music-metadata
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T19:00:24.725Z

Reserved: 2026-10-07T21:07:54.988Z

Link: CVE-2026-107388

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T19:17:01.683

Modified: 2026-10-08T20:46:35.260

Link: CVE-2026-107388

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:15:13Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value