Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107387— music-metadata: Uncontrolled memory allocation in APEv2 parser

Quick assessment

Affected
Borewit music-metadata
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

music-metadata 是一个用于音频和视频媒体文件的元数据解析库。在版本 11.16.0 之前,APEv2 解析器在验证声明的标签项大小是否足以容纳于剩余的标签或文件数据之前,会读取攻击者可控的标签项大小,并为该二进制项分配一个 Uint8Array 数组。因此,构造恶意的小型 APE 文件(包括通过封面图像项)可能触发不成比例的大规模内存分配,而反复或并发解析操作可能导致进程内存耗尽。该漏洞的影响仅限于可用性丧失(即拒绝服务)。此问题已在版本 11.16.0 中修复。

CVSS 6.2 · Medium

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProduct Version RangeStatus
Borewit music-metadata < 11.16.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107387

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
music-metadata: Uncontrolled memory allocation in APEv2 parser
Source: CVE Program / CVE List V5
Vulnerability Description
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the APEv2 parser reads an attacker-controlled tag-item size and allocates a Uint8Array for a binary item before proving that the declared item fits in the remaining tag or file data. A small crafted APE file can therefore trigger a disproportionate allocation, including through cover-art items, and repeated or concurrent parsing can exhaust process memory. The demonstrated impact is availability loss only. This issue is fixed in version 11.16.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的内存分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Borewit music-metadata < 11.16.0 -

II. Public POCs for CVE-2026-107387

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107387

请登录查看更多情报信息。

Other References for CVE-2026-107387 (4)

Same Patch Batch · Borewit · 2026-10-08 · 6 CVEs total

CVE-2026-107388 6.2 MEDIUM music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion
CVE-2026-107390 6.2 MEDIUM music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length
CVE-2026-107389 6.2 MEDIUM music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process
CVE-2026-107392 6.2 MEDIUM music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-3
CVE-2026-107391 6.2 MEDIUM music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — u

IV. Related Vulnerabilities

V. Comments for CVE-2026-107387

No comments yet


Leave a comment