PT-2026-108171 · Npm · Music-Metadata

CVE-2026-107391

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions music-metadata versions 11.14.1 through 11.15.x
Description A regression in the MP4 stsd sample-description parser allows a crafted MP4-family input to cause a denial of service. By providing a sample-entry size of zero and a specific entry count, an attacker can prevent the StsdAtom.get cursor from advancing while keeping the synchronous loop active. This results in the Node.js event loop being blocked and the sample-description table growing until the process exhausts memory or is terminated.
Recommendations Update to version 11.16.0.

Fix

Infinite Loop

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107391
GHSA-F94X-6692-553Q

Affected Products

Music-Metadata