PT-2026-108170 · Npm · Music-Metadata
CVE-2026-107390
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
music-metadata versions prior to 11.16.0
Description
The MP4 parser accepts an attacker-controlled 64-bit extended atom size and converts it to a JavaScript Number. This resulting payload length is used for atom-specific
readToken() calls before verifying if the atom fits within its parent or the available input. A small MP4-family file can trigger an oversized length during payload parsing for atoms such as mvhd, stsd, stsz, and date, leading to a large memory allocation attempt or process failure. This can result in a denial of service for applications parsing untrusted MP4-family media.Recommendations
Update to version 11.16.0.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Music-Metadata