Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 3.6 Node.js & npm GHSA-f94x-6692-553q CVE-2026-107391

CVE-2026-107391 — music-metadata: MP4 stsd sample-entry size==0 can cause synchronous infinite loop (DoS)

A regression in the MP4 stsd sample-description parser in music-metadata can let a crafted MP4-family input trigger a synchronous infinite loop that blocks the process event loop and grows memory until termination or exhaustion. The issue is tracked as CVE-2026-107391 (GHSA-f94x-6692-553q) and is fixed in music-metadata 11.16.0. [sources: 4115, 31908]

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

A regression introduced on the public development branch of music-metadata causes the MP4 stsd sample-description parser to enter a synchronous infinite loop when presented with a crafted sample-entry size of zero and a controlled entry_count. The issue can lead to denial-of-service by blocking the process event loop and exhausting memory. [4115,31908]

What happened

A development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent advancement of the parser cursor while an attacker-controlled entry_count keeps a synchronous loop running. A crafted MP4-family input can therefore block the process event loop and cause the sample-description table to grow until the process is terminated or exhausts memory. The issue is tracked as CVE-2026-107391 (GHSA-f94x-6692-553q). [4115,31908]

Technical cause

The parser's StsdAtom.get cursor does not advance when given a sample-entry size of zero; combined with an attacker-controlled entry_count this keeps a synchronous loop from terminating. This regression arose in a public development revision after 11.14.0. The underlying weakness maps to resource exhaustion (CWE-400). [4115,31908]

Why it matters

A crafted MP4-family file can trigger an infinite synchronous loop in the parser, blocking the process event loop and growing in-memory data structures until the process is terminated or runs out of memory. This results in a denial-of-service condition for any application that parses untrusted MP4-family inputs with the vulnerable code path. [4115,31908]

Who is affected

The change that introduced the regression was present on the public master (development) branch after 11.14.0 but was not included in the music-metadata 11.14.0 release or any earlier release. The OSV record lists the affected range as introduced at 0 and fixed at 11.16.0. Consumers using the vulnerable development revision or any release earlier than 11.16.0 should consider themselves at risk. [4115,31908]

Discovery and timeline

Public records for this issue were published on 2026-10-08 (OSV) and 2026-10-08/2026-10-09 in the NVD entry. The package advisory metadata shows published_at 2026-10-08T19:43:25+02:00 and modified_at 2026-10-09T16:17:22+02:00. The fact package does not provide details about the original reporter, the exact commit, or any intervening changes beyond the stated version range. [4115,31908]

Affected versions

According to the advisory claims, the issue was introduced at version "0" and fixed in "11.16.0". The advisory also notes the regression was introduced after "11.14.0" and not present in "11.14.0" or earlier releases. [4115]

Fixes and mitigation

A fixed release is available: music-metadata version "11.16.0" contains the fix. The advisory indicates fix_available = true and includes a fixed_version claim for "11.16.0". [4115,31908]

Recommended action

Update deployments to music-metadata "11.16.0". Avoid using the vulnerable public development/master revision described in the advisory. Verify that components which parse MP4-family inputs are running the fixed release. [4115]

PatchBriefing score

3.6 / 10 · Low

Official CVSS: 6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

The advisory lists a CVSS v3.1 base score of 6.2 with vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. This reflects a high impact on availability (A:H) with low attack surface (AV:L) and no confidentiality or integrity impact. The PatchWire score for prioritization is 3.6. Contributing factors in the package metadata: cvss_base = 6.2, no known exploitation, no public exploit, no EPSs data, no unauthenticated remote vector, no required user interaction (contribution +0.2), and fix is available. See package score_factors in the advisory for details. [4115,31908]

Affected versions

music-metadata ≥ 0 < 11.16.0
vulnerable
≥ 11.16.0
patched

Reported fixes

A fixed release is available: music-metadata version "11.16.0" contains the fix. The advisory indicates fix_available = true and includes a fixed_version claim for "11.16.0". [4115,31908]

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
CVE-2026-107391 — music-metadata: MP4 stsd sample-entry size==0 can cause synchronous infinite loop (DoS)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email