Description
music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore without awaiting the returned promise and without first rejecting a chunk size smaller than the 12-byte chunk header. A crafted DSF input can produce a negative ignore length; with strtok3 10.3.5 or later, the resulting RangeError is detached from the parseBuffer promise and becomes an unhandled rejection under Node.js default behavior. The parse call can appear to resolve before the process crashes, bypassing per-parse try/catch handling. The demonstrated impact is availability loss only and requires the DSF parsing path. This issue is fixed in version 11.15.0.
Published: 2026-10-08
Score: 6.2 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch Update
AI Analysis

Impact

The DSF parser in music‑metadata incorrectly handles unrecognized chunks by calling tokenizer.ignore without awaiting the returned promise and without rejecting chunks smaller than the 12‑byte header. A crafted DSF file can trigger a negative ignore length, producing a RangeError that, because of the detachment from the parseBuffer promise in strtok3 10.3.5 or later, becomes an unhandled rejection under Node.js default behavior. The parse call may appear to resolve before the crash, bypassing the per‑parse try/catch wrapper; the effect is a process termination that removes the service from availability. Confidentiality and integrity remain unaffected.

Affected Systems

The vulnerability affects the Borewit music‑metadata library prior to version 11.15.0. Any Node.js application that parses DSF files using an older release of this library is potentially impacted.

Risk and Exploitability

The CVSS score of 6.2 indicates moderate severity; EPSS data is not available and the issue is not listed in CISA KEV. The attack vector is inferred to be the delivery of a malicious DSF file to any code path that invokes the music‑metadata parser. No special privileges or additional components are required. An attacker can repeatedly supply crafted DSF files to repeatedly crash or starve a long‑running service, constituting a denial‑of‑service attack.

Generated by OpenCVE AI on October 8, 2026 at 21:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to music‑metadata v11.15.0 or later, which removes the unawaited ignore call and the RangeError detachment path.
  • If an upgrade cannot be performed immediately, isolate DSF parsing in a separate process or sandbox to contain any crash from affecting the main application.
  • When upgrading is not an option, lock the strtok3 dependency to a version earlier than 10.3.5 to avoid the range‑detachment behavior that triggers the crash.

Generated by OpenCVE AI on October 8, 2026 at 21:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-8j4c-6x6g-rq3j music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of GHSA-v6c2-xwv6-8xf7)
History

Thu, 08 Oct 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Borewit
Borewit music-metadata
Vendors & Products Borewit
Borewit music-metadata

Thu, 08 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore without awaiting the returned promise and without first rejecting a chunk size smaller than the 12-byte chunk header. A crafted DSF input can produce a negative ignore length; with strtok3 10.3.5 or later, the resulting RangeError is detached from the parseBuffer promise and becomes an unhandled rejection under Node.js default behavior. The parse call can appear to resolve before the process crashes, bypassing per-parse try/catch handling. The demonstrated impact is availability loss only and requires the DSF parsing path. This issue is fixed in version 11.15.0.
Title music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-32256)
Weaknesses CWE-248
CWE-400
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Borewit Music-metadata
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-08T19:53:23.640Z

Reserved: 2026-10-07T21:07:54.989Z

Link: CVE-2026-107392

cve-icon Vulnrichment

Updated: 2026-10-08T19:53:19.758Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-08T20:17:33.707

Modified: 2026-10-08T20:46:35.260

Link: CVE-2026-107392

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T20:45:14Z

Weaknesses
  • CWE-248

    Uncaught Exception

  • CWE-400

    Uncontrolled Resource Consumption