Description
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the MP4 parser accepts an attacker-controlled 64-bit extended atom size, converts it to a JavaScript Number, and uses the resulting payload length for atom-specific readToken calls before proving that the atom fits within its parent or the available input. A tiny MP4-family file can route an oversized length into payload parsing for atoms including mvhd, stsd, stsz, and date, causing a large allocation attempt or process failure before end-of-input validation. Applications that parse untrusted MP4-family media can therefore be denied service. This issue is fixed in version 11.16.0.
Published: 2026-10-08
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Memory Exhaustion (Denial of Service)
Action: Patch ASAP
AI Analysis

Impact

The MP4 parser in music‑metadata accepts a 64‑bit extended atom size supplied by the file header, converts it to a JavaScript Number, and uses that value as the length for subsequent read operations before verifying that the atom fits within its parent or the remaining input. A maliciously crafted MP4 file can therefore convey an oversized length that leads the parser to attempt an extremely large allocation or to crash the process during payload parsing for atoms such as mvhd, stsd, stsz, or date. The resulting memory exhaustion or failure causes the host application to become unresponsive, effectively denying service. This vulnerability is specific to the parsing of MP4‑family files and exploits an improper bounds check identified as CWE‑789.

Affected Systems

The affected product is the Borewit music‑metadata library, with all releases prior to version 11.16.0 vulnerable. Applications that embed or import this library to process user‑supplied MP4 or related media files are at risk, regardless of the hosting environment. The issue does not affect native media players that do not use music‑metadata.

Risk and Exploitability

The CVSS score of 6.2 indicates a moderate severity, and the EPSS score is not available, meaning no current data on exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker providing a crafted MP4 file to the application, either through local file upload or remote media ingestion, which triggers the excessive memory allocation and leads to denial of service. No authentication or elevated privileges are required, allowing remote unauthenticated exploitation if the application exposes a file processing endpoint.

Generated by OpenCVE AI on October 8, 2026 at 21:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade music‑metadata to version 11.16.0 or later, which removes the vulnerability by validating atom sizes before allocation.
  • Configure the MP4 parsing environment to run in a sandbox or container with capped memory limits, preventing a single oversized allocation from exhausting host resources.
  • Apply a preliminary file‑size or atom‑length validation at the application layer, rejecting any MP4 file that declares an atom larger than a defined safe threshold before invoking the parser.

Generated by OpenCVE AI on October 8, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Borewit
Borewit music-metadata
Vendors & Products Borewit
Borewit music-metadata

Thu, 08 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the MP4 parser accepts an attacker-controlled 64-bit extended atom size, converts it to a JavaScript Number, and uses the resulting payload length for atom-specific readToken calls before proving that the atom fits within its parent or the available input. A tiny MP4-family file can route an oversized length into payload parsing for atoms including mvhd, stsd, stsz, and date, causing a large allocation attempt or process failure before end-of-input validation. Applications that parse untrusted MP4-family media can therefore be denied service. This issue is fixed in version 11.16.0.
Title music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Borewit Music-metadata
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T11:47:21.464Z

Reserved: 2026-10-07T21:07:54.988Z

Link: CVE-2026-107390

cve-icon Vulnrichment

Updated: 2026-10-09T11:47:16.795Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-10-08T20:17:33.357

Modified: 2026-10-09T12:17:08.590

Link: CVE-2026-107390

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:15:13Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value