Description
music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0.
Published: 2026-10-08
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

music-metadata is a Node.js library used to extract metadata from audio and video files. A regression introduced after 11.14.0 in the MP4 stsd sample-description parser allows an attacker to craft a sample-entry with a size of zero. This prevents the internal cursor from advancing while an attacker-controlled entry_count keeps a synchronous loop running, which blocks the Node.js event loop and can grow the sample-description table until the process is terminated or memory is exhausted. The resulting denial of service is the primary impact.

Affected Systems

The vulnerability resides in the Borewit:music-metadata package. Any Node.js project that relies on a version earlier than 11.16.0 and processes MP4-family files is affected. The regression was present in the public master branch but did not appear in releases up to 11.14.0. The fix is included in release 11.16.0 and subsequent versions.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity, and the vulnerability is not listed in the CISA KEV catalog. EPSS data is currently unavailable, so the exploitation probability is unknown. An attacker can exploit this by delivering a malicious MP4 file either locally or through a media ingestion endpoint. While no remote code execution is possible, the denial‑of‑service nature can disrupt services or deplete memory resources, making it a noteworthy concern for applications that handle user‑supplied media.

Generated by OpenCVE AI on October 8, 2026 at 20:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade music‑metadata to version 11.16.0 or later to apply the official fix.
  • If an upgrade is not feasible, reject or pre‑validate MP4 files from untrusted sources or perform size validation before parsing to avoid the zero-size sample-entry scenario.
  • Run a dependency audit (npm audit) to ensure no other vulnerable packages are present, and monitor project dependencies for future updates.

Generated by OpenCVE AI on October 8, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f94x-6692-553q music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master
History

Thu, 08 Oct 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Borewit
Borewit music-metadata
Vendors & Products Borewit
Borewit music-metadata

Thu, 08 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0.
Title music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master
Weaknesses CWE-400
CWE-835
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Borewit Music-metadata
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T19:10:47.365Z

Reserved: 2026-10-07T21:07:54.988Z

Link: CVE-2026-107391

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T20:17:33.530

Modified: 2026-10-08T20:46:35.260

Link: CVE-2026-107391

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T21:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-835

    Loop with Unreachable Exit Condition ('Infinite Loop')