Low · 3.6 Node.js & npm GHSA-5gfj-9q3v-qfp3 CVE-2026-107389
music-metadata: EBML VINT length trusted, allowing memory exhaustion (CVE-2026-107389)
An EBML parser in music-metadata trusted an attacker-controlled VINT element length when allocating strings or Uint8Arrays, allowing crafted WebM/MKV/MKA inputs to cause disproportionate memory allocations, out-of-memory denial-of-service, or an uncatchable runtime abort observed on a demonstrated parse path. The issue is fixed in 11.16.0. (CVE-2026-107389)
AI summary
A flaw in the EBML (Matroska/WebM) parsing logic of the music-metadata npm package lets an attacker-controlled VINT element length be used for allocations before validating that the decoded leaf actually fits. This can lead to excessive memory consumption, denial of service, and in a demonstrated parse path result in an uncatchable fatal abort. The vendor fixed the issue in 11.16.0. Source: OSV and NVD.
What happened
The music-metadata EBML/WebM parser decodes an attacker-controlled VINT element length and uses that value to allocate string tokens or Uint8Array buffers before confirming the decoded leaf fits within its parent element or the available input. Crafted WebM, MKV, or MKA files can therefore trigger disproportionate allocations and out-of-memory denial-of-service. In addition, an uncatchable fatal abort was observed on a demonstrated parseFile path running on runtime 26.7.0. The flaw affects availability only and does not affect confidentiality or integrity according to the available reports. (source items: 4112, 31906)
Technical cause
The parser trusts a decoded VINT element length and uses it directly for string-token or Uint8Array allocation before validating that the leaf fits inside its parent element or the remaining input. This missing leaf-length validation across the tokenizer and parser allows crafted inputs to force excessive allocations or to trigger a fatal runtime abort in some environments. (source items: 4112, 31906)
Why it matters
The vulnerability has an availability impact only: attackers can cause memory exhaustion or crash the process when parsing specially crafted EBML-based media files. The assigned CVSS v3.1 base score is 6.2 (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H), reflecting local attack vector with high impact to availability but no confidentiality or integrity loss. The PatchWire urgency score for this advisory is 3.6, derived primarily from the CVSS base score and the fact that no user interaction is required to trigger the issue. (source items: 4112, 31906)
Who is affected
Projects and systems that use the music-metadata package to parse Matroska/WebM EBML content (for example MKV, MKA, or WebM files) and that run a vulnerable release of music-metadata may be affected. Attackers able to supply crafted media files to the parsing context can trigger the issue. (source items: 4112, 31906)
Discovery and timeline
The vulnerability was published in OSV.dev on 2026-10-08 and is listed in the NVD entry for CVE-2026-107389 on 2026-10-08. The OSV entry and the NVD record provide the details used in this briefing. (source items: 4112, 31906)
Affected versions
All releases of music-metadata from introduced version 0 up to, but not including, 11.16.0 are affected. (source items: 4112)
Fixes and mitigation
The issue is fixed in music-metadata version 11.16.0. Users should update to 11.16.0. If an immediate upgrade is not possible, consider parsing untrusted EBML-based media in a restricted environment (separate process with memory limits) or pre-validating container structure before handing data to the vulnerable parser. (source items: 4112)
Recommended action
Upgrade music-metadata to 11.16.0 as soon as practicable. Treat untrusted EBML-based media (WebM, MKV, MKA) as potentially malformed and avoid parsing it in high-privilege or unrestricted-memory processes. (source items: 4112)
PatchBriefing score
3.6 / 10 · Low
Official CVSS: 6.2
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Why this score
CVSS v3.1 base score: 6.2 (AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). PatchWire score: 3.6. The PatchWire score is composed mainly from the CVSS base contribution (3.41) plus a small contribution for no user interaction required (0.2); other factors such as known exploitation or public exploits contributed zero. (source items: 4112, 31906)
Affected versions
- music-metadata ≥ 0 < 11.16.0
- vulnerable
- ≥ 11.16.0
- patched
Reported fixes
The issue is fixed in music-metadata version 11.16.0. Users should update to 11.16.0. If an immediate upgrade is not possible, consider parsing untrusted EBML-based media in a restricted environment (separate process with memory limits) or pre-validating container structure before handing data to the vulnerable parser. (source items: 4112)
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email