CVE-2026-107391
Awaiting Analysis Awaiting Analysis - Queue

MP4 Sample-Description Parser DoS in music-metadata

Vulnerability report for CVE-2026-107391, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Borewit music-metadata < 11.16.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
CWE-835 The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

music-metadata is a library for parsing metadata from audio and video files. A regression in the MP4 parser allows an attacker to create a malformed MP4 file with a zero sample-entry size. This causes the parser to get stuck in a loop, blocking the Node.js event loop and consuming excessive memory until the process crashes.

Detection Guidance

Detection involves checking for music-metadata versions between 11.14.0 and 11.16.0. Use commands like 'npm list music-metadata' or 'find package.json -exec grep music-metadata {};' to identify affected installations.

Impact Analysis

If you process untrusted MP4 files using a vulnerable version of music-metadata, an attacker could craft a file to freeze or crash your application. This could lead to denial-of-service, disrupting services that rely on media processing.

Compliance Impact

This vulnerability primarily causes denial-of-service conditions by blocking the event loop and exhausting memory, which could disrupt system availability. While it does not directly expose or leak data, prolonged downtime may impact compliance with availability requirements in standards like GDPR (data processing integrity) and HIPAA (system availability for protected health information).

Mitigation Strategies

Upgrade music-metadata to version 11.16.0 or later. If using npm, run 'npm update music-metadata'. For manual installations, replace the library with the patched version.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107391. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart