Description
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser decodes an attacker-controlled VINT element length and uses it for string-token or Uint8Array allocation before confirming that the leaf fits within its parent or available input. Crafted WebM, MKV, or MKA inputs can cause disproportionate allocations, out-of-memory denial of service, or, for a demonstrated parseFile path on Node.js 26.7.0, an uncatchable V8 fatal abort. The exact failure mode depends on the tokenizer, parser API, and runtime, but the affected leaf-length validation flaw is shared and has availability impact only. This issue is fixed in version 11.16.0.
Published: 2026-10-08
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service via excessive memory allocation or process termination
Action: Apply Patch
AI Analysis

Impact

The music‑metadata library contains a flaw in the EBML parser where the length of a VINT element is trusted before checking that its leaf fits within its parent. An attacker can craft WebM, MKV, or MKA files that cause the parser to allocate an oversized string or array, leading to an out‑of‑memory denial of service, or in some runtimes trigger an uncatchable V8 fatal abort. The vulnerability results in a loss of availability for any process that parses untrusted media.

Affected Systems

Vulnerable versions of Borewit music‑metadata fall before 11.16.0. The flaw is present in the Matroska and WebM EBML parsing code used by Node.js applications that import or analyze audio and video files. Environments running Node.js 26.7.0 with the parseFile API show the most severe manifestation of the fault.

Risk and Exploitability

The CVSS score is 6.2, indicating moderate severity. EPSS is not available and there is no current listing in the CISA KEV catalog, so there is no documented exploitation, though the vulnerability can be triggered by supplying a specially crafted media file. The attack vector is likely remote through any interface that accepts untrusted media, but this inference comes from the description; local files can also be used. Exploitation would consume system memory until the process is killed or the runtime aborts, causing a denied service for the affected application.

Generated by OpenCVE AI on October 8, 2026 at 21:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to music‑metadata version 11.16.0 or later, which contains the parser fix.
  • If an upgrade cannot be performed immediately, validate the size of incoming media files and enforce strict limits before feeding them to the parser to prevent oversized allocations.
  • Apply additional process‑level safeguards such as memory limits or sandboxing to contain any potential denial‑of‑service impact until the library can be updated.

Generated by OpenCVE AI on October 8, 2026 at 21:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-5gfj-9q3v-qfp3 music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort
History

Thu, 08 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Borewit
Borewit music-metadata
Vendors & Products Borewit
Borewit music-metadata

Thu, 08 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser decodes an attacker-controlled VINT element length and uses it for string-token or Uint8Array allocation before confirming that the leaf fits within its parent or available input. Crafted WebM, MKV, or MKA inputs can cause disproportionate allocations, out-of-memory denial of service, or, for a demonstrated parseFile path on Node.js 26.7.0, an uncatchable V8 fatal abort. The exact failure mode depends on the tokenizer, parser API, and runtime, but the affected leaf-length validation flaw is shared and has availability impact only. This issue is fixed in version 11.16.0.
Title music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Borewit Music-metadata
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T19:05:23.816Z

Reserved: 2026-10-07T21:07:54.988Z

Link: CVE-2026-107389

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T20:17:33.190

Modified: 2026-10-08T20:46:35.260

Link: CVE-2026-107389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:45:16Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value