music-metadata 是一个用于解析音频和视频媒体文件元数据的库。在 11.14.0 版本之后引入的公共开发版本中,MP4 stsd(样本描述)解析器存在一个开发分支回归缺陷。攻击者可利用将样本入口(sample-entry)大小设置为零,导致 StsdAtom.get 方法的游标无法前进;同时,攻击者可控制的 entry_count 会使同步循环持续运行。通过构造特定的 MP4 系列输入文件,攻击者可以阻塞 Node.js 事件循环,并不断膨胀样本描述表,直到进程被终止或耗尽内存为止。 该漏洞代码存在于公
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Borewit | music-metadata | < 11.16.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Borewit | music-metadata | < 11.16.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107387 | 6.2 MEDIUM | music-metadata: Uncontrolled memory allocation in APEv2 parser |
| CVE-2026-107388 | 6.2 MEDIUM | music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion |
| CVE-2026-107390 | 6.2 MEDIUM | music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length |
| CVE-2026-107389 | 6.2 MEDIUM | music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process |
| CVE-2026-107392 | 6.2 MEDIUM | music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-3 |
No comments yet