Description
A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metadata Handler. This manipulation causes denial of service. The attack needs to be launched locally. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Published: 2026-07-09
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Metadata Handler of the pdeljanov Symphonia library and permits a local attacker to trigger a denial of service by manipulating metadata content. The flaw results in an application crash or resource exhaustion, without providing any other compromise.

Affected Systems

All releases of Symphonia up to and including version 0.6.0 are affected. The flaw resides in the Metadata Handler component, which is invoked when processing media files or other data that contains metadata.

Risk and Exploitability

The EPSS score is < 1%, indicating a very low probability of exploitation, and the attacker must launch the attack locally. An exploit has been published, and it might be used against systems that can run code locally. The vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation.

Generated by OpenCVE AI on July 28, 2026 at 08:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for an official Symphonia release that integrates the fix from PR 514 and upgrade when available.
  • the Metadata Handler for untrusted files or temporarily disable the component.
  • Restrict local user privileges on machines running Symphonia, limiting the ability of an attacker to trigger the denial of service—e.g., run the library within a sandbox or container.

Generated by OpenCVE AI on July 28, 2026 at 08:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in pdeljanov Symphonia up to 0.6.0. This vulnerability affects unknown code of the component Metadata Handler. This manipulation causes denial of service. The attack needs to be launched locally. The exploit has been published and may be used. The pull request to fix this issue awaits acceptance.
Title pdeljanov Symphonia Metadata denial of service
First Time appeared Pdeljanov
Pdeljanov symphonia
Weaknesses CWE-404
CPEs cpe:2.3:a:pdeljanov:symphonia:*:*:*:*:*:*:*:*
Vendors & Products Pdeljanov
Pdeljanov symphonia
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Pdeljanov Symphonia
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-10T18:24:06.793Z

Reserved: 2026-07-09T15:02:29.634Z

Link: CVE-2026-15276

cve-icon Vulnrichment

Updated: 2026-07-10T18:24:02.422Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:45:04Z

Weaknesses
  • CWE-404

    Improper Resource Shutdown or Release