Low · 3.6 Node.js & npm GHSA-f94x-6692-553q CVE-2026-107391
CVE-2026-107391 — music-metadata: MP4 stsd sample-entry size==0 can cause synchronous infinite loop (DoS)
A regression in the MP4 stsd sample-description parser in music-metadata can let a crafted MP4-family input trigger a synchronous infinite loop that blocks the process event loop and grows memory until termination or exhaustion. The issue is tracked as CVE-2026-107391 (GHSA-f94x-6692-553q) and is fixed in music-metadata 11.16.0. [sources: 4115, 31908]
AI summary
A regression introduced on the public development branch of music-metadata causes the MP4 stsd sample-description parser to enter a synchronous infinite loop when presented with a crafted sample-entry size of zero and a controlled entry_count. The issue can lead to denial-of-service by blocking the process event loop and exhausting memory. [4115,31908]
What happened
A development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent advancement of the parser cursor while an attacker-controlled entry_count keeps a synchronous loop running. A crafted MP4-family input can therefore block the process event loop and cause the sample-description table to grow until the process is terminated or exhausts memory. The issue is tracked as CVE-2026-107391 (GHSA-f94x-6692-553q). [4115,31908]
Technical cause
The parser's StsdAtom.get cursor does not advance when given a sample-entry size of zero; combined with an attacker-controlled entry_count this keeps a synchronous loop from terminating. This regression arose in a public development revision after 11.14.0. The underlying weakness maps to resource exhaustion (CWE-400). [4115,31908]
Why it matters
A crafted MP4-family file can trigger an infinite synchronous loop in the parser, blocking the process event loop and growing in-memory data structures until the process is terminated or runs out of memory. This results in a denial-of-service condition for any application that parses untrusted MP4-family inputs with the vulnerable code path. [4115,31908]
Who is affected
The change that introduced the regression was present on the public master (development) branch after 11.14.0 but was not included in the music-metadata 11.14.0 release or any earlier release. The OSV record lists the affected range as introduced at 0 and fixed at 11.16.0. Consumers using the vulnerable development revision or any release earlier than 11.16.0 should consider themselves at risk. [4115,31908]
Discovery and timeline
Public records for this issue were published on 2026-10-08 (OSV) and 2026-10-08/2026-10-09 in the NVD entry. The package advisory metadata shows published_at 2026-10-08T19:43:25+02:00 and modified_at 2026-10-09T16:17:22+02:00. The fact package does not provide details about the original reporter, the exact commit, or any intervening changes beyond the stated version range. [4115,31908]
Affected versions
According to the advisory claims, the issue was introduced at version "0" and fixed in "11.16.0". The advisory also notes the regression was introduced after "11.14.0" and not present in "11.14.0" or earlier releases. [4115]
Fixes and mitigation
A fixed release is available: music-metadata version "11.16.0" contains the fix. The advisory indicates fix_available = true and includes a fixed_version claim for "11.16.0". [4115,31908]
Recommended action
Update deployments to music-metadata "11.16.0". Avoid using the vulnerable public development/master revision described in the advisory. Verify that components which parse MP4-family inputs are running the fixed release. [4115]
PatchBriefing score
3.6 / 10 · Low
Official CVSS: 6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
The advisory lists a CVSS v3.1 base score of 6.2 with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. This reflects a high impact on availability (A:H) with low attack surface (AV:L) and no confidentiality or integrity impact. The PatchWire score for prioritization is 3.6. Contributing factors in the package metadata: cvss_base = 6.2, no known exploitation, no public exploit, no EPSs data, no unauthenticated remote vector, no required user interaction (contribution +0.2), and fix is available. See package score_factors in the advisory for details. [4115,31908]
Affected versions
- music-metadata ≥ 0 < 11.16.0
- vulnerable
- ≥ 11.16.0
- patched
Reported fixes
A fixed release is available: music-metadata version "11.16.0" contains the fix. The advisory indicates fix_available = true and includes a fixed_version claim for "11.16.0". [4115,31908]
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email