Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107390— music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length

Quick assessment

Affected
Borewit music-metadata
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

music-metadata 是一个用于解析音视频媒体文件元数据的库。在版本 11.16.0 之前,其 MP4 解析器会接受攻击者可控的 64 位扩展原子(atom)大小,并将其转换为 JavaScript 的 Number 类型,随后在未验证该原子是否位于其父容器内或是否超出可用输入数据范围的情况下,直接使用计算出的负载长度进行与原子类型相关的 readToken 读取操作。这种缺陷使得一个极小的 MP4 系列文件能够将过大的长度值引入到对 mvhd、stsd、stsz 和 date 等原子的负载解析中,从而在到

CVSS 6.2 · Medium

Affected Version Matrix 1

VendorProduct Version RangeStatus
Borewit music-metadata < 11.16.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107390

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length
Source: CVE Program / CVE List V5
Vulnerability Description
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the MP4 parser accepts an attacker-controlled 64-bit extended atom size, converts it to a JavaScript Number, and uses the resulting payload length for atom-specific readToken calls before proving that the atom fits within its parent or the available input. A tiny MP4-family file can route an oversized length into payload parsing for atoms including mvhd, stsd, stsz, and date, causing a large allocation attempt or process failure before end-of-input validation. Applications that parse untrusted MP4-family media can therefore be denied service. This issue is fixed in version 11.16.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未经控制的内存分配
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Borewit music-metadata < 11.16.0 -

II. Public POCs for CVE-2026-107390

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107390

请登录查看更多情报信息。

Other References for CVE-2026-107390 (4)

Same Patch Batch · Borewit · 2026-10-08 · 6 CVEs total

CVE-2026-107387 6.2 MEDIUM music-metadata: Uncontrolled memory allocation in APEv2 parser
CVE-2026-107388 6.2 MEDIUM music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion
CVE-2026-107389 6.2 MEDIUM music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process
CVE-2026-107392 6.2 MEDIUM music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-3
CVE-2026-107391 6.2 MEDIUM music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — u

IV. Related Vulnerabilities

V. Comments for CVE-2026-107390

No comments yet


Leave a comment