CVE-2026-107390
Awaiting Analysis Awaiting Analysis - Queue

MP4 Atom Size Handling DoS in music-metadata

Vulnerability report for CVE-2026-107390, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the MP4 parser accepts an attacker-controlled 64-bit extended atom size, converts it to a JavaScript Number, and uses the resulting payload length for atom-specific readToken calls before proving that the atom fits within its parent or the available input. A tiny MP4-family file can route an oversized length into payload parsing for atoms including mvhd, stsd, stsz, and date, causing a large allocation attempt or process failure before end-of-input validation. Applications that parse untrusted MP4-family media can therefore be denied service. This issue is fixed in version 11.16.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Borewit music-metadata < 11.16.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-789 The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

music-metadata is a library for parsing metadata from audio and video files. A vulnerability exists in versions before 11.16.0 where the MP4 parser processes an attacker-controlled atom size without proper validation. This allows an attacker to specify a large size that causes excessive memory allocation or crashes during parsing.

Detection Guidance

To detect this vulnerability, check the version of music-metadata in use. If your application uses versions 11.12.3 or earlier, it is vulnerable. Update to version 11.16.0 or later to mitigate the risk. No specific commands are provided in the context for detection, but monitoring for crashes or high memory usage when processing MP4 files may indicate exploitation attempts.

Impact Analysis

If you use an affected version of music-metadata to parse untrusted MP4 files, an attacker could craft a malicious file that causes your application to crash or consume excessive memory. This could lead to denial-of-service conditions for applications relying on this library.

Compliance Impact

This vulnerability primarily impacts availability by causing denial-of-service through memory exhaustion. It does not directly affect data confidentiality or integrity, which are key concerns for GDPR and HIPAA. However, service disruption could indirectly impact compliance by preventing access to personal or health data during outages.

Mitigation Strategies

Update music-metadata to version 11.16.0 or later to address the vulnerability. If using a package manager, run commands like npm update music-metadata or equivalent for your environment.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107390. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart