PT-2026-108172 · Npm+1 · Strtok3+2

CVE-2026-107392

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions music-metadata versions prior to 11.15.0
Description The DSF parser handles unrecognized chunks by calling tokenizer.ignore() without awaiting the returned promise and without rejecting chunk sizes smaller than the 12-byte chunk header. A specially crafted DSF input can trigger a negative ignore length. When used with strtok3 10.3.5 or later, this results in a RangeError that is detached from the parseBuffer promise, leading to an unhandled rejection in Node.js. This can cause the process to crash, bypassing per-parse try/catch error handling and resulting in a loss of availability.
Recommendations Update to version 11.15.0.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107392
GHSA-8J4C-6X6G-RQ3J

Affected Products

Node.Js
Music-Metadata
Strtok3