Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Low · 3.6 Node.js & npm GHSA-jjpr-9cvf-cq55 CVE-2026-107388

music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS (CVE-2026-107388)

An ID3v2 parser in music-metadata allocates memory based on the syncsafe tag-size without verifying input length, allowing a truncated file to trigger a large allocation and cause an availability-impacting failure. A fix is available in 11.16.0.

Synthesized by AI from 3 sources · updated 1 hour ago

AI summary

The music-metadata library contains an ID3v2 parsing bug where the declared syncsafe tag-size is used to allocate the tag body before the parser confirms that the input stream contains that many bytes. Truncated inputs can therefore trigger a large allocation and an internal read error while the caller still receives a metadata object. The issue is tracked as CVE-2026-107388 and fixed in 11.16.0.

What happened

The ID3v2 parser in music-metadata trusts the syncsafe tag-size field and allocates memory for the full tag body before checking whether the input actually contains the declared number of bytes. A truncated file containing only an ID3v2 header can request an allocation approaching 268 MiB; the allocation succeeds, the subsequent read reaches end of stream, the internal EndOfStreamError is caught, and the caller receives a normal metadata object despite the truncated input. This behavior can lead to memory exhaustion and an availability impact. (Sources: 4114, 9015, 31888)

Technical cause

The parser uses the syncsafe tag-size value from the ID3v2 header to allocate the complete tag body before validating that the input contains the declared bytes. This unchecked allocation is the root cause, and the issue is categorized under CWE-789 (uncontrolled memory allocation). (Sources: 4114, 9015, 31888)

Why it matters

The flaw can cause large memory allocations and lead to denial of service (availability impact) when processing crafted or truncated media files. The computed CVSS v3.1 base score is 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Patchwire assigns a remediation priority score of 3.6 for this issue. There are no known public exploits or reports of active exploitation in the provided sources. (Sources: 4114, 9015, 31888)

Who is affected

Projects that use the music-metadata npm package are affected. The advisory indicates the issue exists in releases introduced at version 0 and is fixed in 11.16.0. (Sources: 4114, 9015, 31888)

Discovery and timeline

The vulnerability is cataloged in public databases with publication entries on 2026-10-08 (sources list published timestamps around that date). The OSV entry and CVE/NVD records document the issue. (Sources: 4114, 9015, 31888)

Affected versions

The advisory reports the affected range as introduced at 0 and fixed in 11.16.0. Users running any release prior to 11.16.0 are in the affected range described by the sources. (Sources: 4114, 9015, 31888)

Fixes and mitigation

A fix is available in the vendor update 11.16.0. The sources list 11.16.0 as the fixed version. (Sources: 4114, 9015, 31888)

Recommended action

Update instances of music-metadata to 11.16.0. The published advisories identify 11.16.0 as the release that contains the fix. (Sources: 4114, 9015, 31888)

PatchBriefing score

3.6 / 10 · Low

Official CVSS: 6.2

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Why this score

CVSS v3.1 base score 6.2 (vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects a local attack vector with low attack complexity and no confidentiality or integrity impact but high availability impact. Patchwire score is 3.6 based on the CVSS base score and the lack of reported public exploitation. (Sources: 4114, 9015, 31888)

Affected versions

music-metadata ≥ 0 < 11.16.0
vulnerable
≥ 11.16.0
patched

Reported fixes

A fix is available in the vendor update 11.16.0. The sources list 11.16.0 as the fixed version. (Sources: 4114, 9015, 31888)

How this was built

3 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • CVE.org database
  • NVD (NIST) database
Unified report
music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS (CVE-2026-107388)
1 article · 3 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email