PT-2026-108171 · Npm · Music-Metadata
CVE-2026-107391
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
music-metadata versions 11.14.1 through 11.15.x
Description
A regression in the MP4 stsd sample-description parser allows a crafted MP4-family input to cause a denial of service. By providing a sample-entry size of zero and a specific
entry count, an attacker can prevent the StsdAtom.get cursor from advancing while keeping the synchronous loop active. This results in the Node.js event loop being blocked and the sample-description table growing until the process exhausts memory or is terminated.Recommendations
Update to version 11.16.0.
Fix
Infinite Loop
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Music-Metadata