CVE-2026-107389
Awaiting Analysis Awaiting Analysis - Queue

Memory Exhaustion in music-metadata Matroska Parser

Vulnerability report for CVE-2026-107389, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser decodes an attacker-controlled VINT element length and uses it for string-token or Uint8Array allocation before confirming that the leaf fits within its parent or available input. Crafted WebM, MKV, or MKA inputs can cause disproportionate allocations, out-of-memory denial of service, or, for a demonstrated parseFile path on Node.js 26.7.0, an uncatchable V8 fatal abort. The exact failure mode depends on the tokenizer, parser API, and runtime, but the affected leaf-length validation flaw is shared and has availability impact only. This issue is fixed in version 11.16.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Borewit music-metadata < 11.16.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the music-metadata library, which parses metadata from audio and video files. The issue is in the Matroska and WebM EBML parser, which decodes attacker-controlled element lengths before validating if they fit within the file or container. This can lead to disproportionate memory allocations, causing denial-of-service or process aborts when processing crafted WebM, MKV, or MKA files.

Detection Guidance

Detecting this vulnerability requires checking the version of music-metadata in use. Run 'npm list music-metadata' or inspect package.json to verify if the installed version is 11.12.3 or earlier. Additionally, monitor for crashes or excessive memory usage when processing Matroska/WebM files.

Impact Analysis

An attacker could exploit this by providing a maliciously crafted media file that triggers excessive memory allocation or crashes the application. This may lead to system slowdowns, application failures, or complete denial of service. The impact depends on the runtime and parser API but primarily affects availability.

Compliance Impact

This vulnerability primarily impacts availability by causing denial-of-service conditions or process aborts through excessive memory allocation. It does not directly compromise confidentiality or integrity of data. Compliance with standards like GDPR or HIPAA is indirectly affected if the denial-of-service disrupts systems handling personal or health data, potentially leading to service unavailability or data processing interruptions.

Mitigation Strategies

Upgrade music-metadata to version 11.16.0 or later immediately. Use 'npm update music-metadata' or specify the fixed version in package.json. Avoid processing untrusted Matroska/WebM files until patched. Monitor system resources for abnormal memory usage.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107389. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart