music-metadata 是一个用于音频和视频媒体文件的元数据解析库。在版本 11.16.0 之前,APEv2 解析器在验证声明的标签项大小是否足以容纳于剩余的标签或文件数据之前,会读取攻击者可控的标签项大小,并为该二进制项分配一个 Uint8Array 数组。因此,构造恶意的小型 APE 文件(包括通过封面图像项)可能触发不成比例的大规模内存分配,而反复或并发解析操作可能导致进程内存耗尽。该漏洞的影响仅限于可用性丧失(即拒绝服务)。此问题已在版本 11.16.0 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Borewit | music-metadata | < 11.16.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Borewit | music-metadata | < 11.16.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107388 | 6.2 MEDIUM | music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion |
| CVE-2026-107390 | 6.2 MEDIUM | music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length |
| CVE-2026-107389 | 6.2 MEDIUM | music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process |
| CVE-2026-107392 | 6.2 MEDIUM | music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-3 |
| CVE-2026-107391 | 6.2 MEDIUM | music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — u |
No comments yet