PT-2026-108172 · Npm+1 · Strtok3+2
CVE-2026-107392
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
music-metadata versions prior to 11.15.0
Description
The DSF parser handles unrecognized chunks by calling
tokenizer.ignore() without awaiting the returned promise and without rejecting chunk sizes smaller than the 12-byte chunk header. A specially crafted DSF input can trigger a negative ignore length. When used with strtok3 10.3.5 or later, this results in a RangeError that is detached from the parseBuffer promise, leading to an unhandled rejection in Node.js. This can cause the process to crash, bypassing per-parse try/catch error handling and resulting in a loss of availability.Recommendations
Update to version 11.15.0.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Node.Js
Music-Metadata
Strtok3