Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107388— music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS

Quick assessment

Affected
Borewit music-metadata
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

music-metadata 是一个用于解析音频和视频媒体文件元数据的工具库。在版本 11.16.0 之前,ID3v2 解析器会信任 syncsafe 标签大小字段,并在验证输入数据是否包含所声明的字节数之前,预先分配整个标签体的内存空间。对于仅包含 ID3v2 文件头的截断文件,系统可能请求分配接近 268 MiB 的内存;尽管分配成功,后续读取操作会到达文件末尾,此时内部会捕获 EndOfStreamError,最终调用方仍会收到一个正常的元数据对象。该问题已在 11.16.0 版本中得到修复。

CVSS 6.2 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Borewit music-metadata < 11.16.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107388

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS
Source: CVE Program / CVE List V5
Vulnerability Description
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe tag-size field and allocates the complete tag body before checking whether the input contains the declared bytes. A truncated file containing only an ID3v2 header can request an allocation approaching 268 MiB; the allocation succeeds, the subsequent read reaches end of stream, the EndOfStreamError is caught internally, and the caller receives a normal metadata object. This issue is fixed in version 11.16.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的内存分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Borewit music-metadata < 11.16.0 -

II. Public POCs for CVE-2026-107388

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107388

请登录查看更多情报信息。

Other References for CVE-2026-107388 (4)

Same Patch Batch · Borewit · 2026-10-08 · 6 CVEs total

CVE-2026-107387 6.2 MEDIUM music-metadata: Uncontrolled memory allocation in APEv2 parser
CVE-2026-107390 6.2 MEDIUM music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length
CVE-2026-107389 6.2 MEDIUM music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process
CVE-2026-107392 6.2 MEDIUM music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-3
CVE-2026-107391 6.2 MEDIUM music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — u

IV. Related Vulnerabilities

V. Comments for CVE-2026-107388

No comments yet


Leave a comment