Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107391— music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master

Quick assessment

Affected
Borewit music-metadata
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

music-metadata 是一个用于解析音频和视频媒体文件元数据的库。在 11.14.0 版本之后引入的公共开发版本中,MP4 stsd(样本描述)解析器存在一个开发分支回归缺陷。攻击者可利用将样本入口(sample-entry)大小设置为零,导致 StsdAtom.get 方法的游标无法前进;同时,攻击者可控制的 entry_count 会使同步循环持续运行。通过构造特定的 MP4 系列输入文件,攻击者可以阻塞 Node.js 事件循环,并不断膨胀样本描述表,直到进程被终止或耗尽内存为止。 该漏洞代码存在于公

CVSS 6.2 · Medium

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProduct Version RangeStatus
Borewit music-metadata < 11.16.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107391

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master
Source: CVE Program / CVE List V5
Vulnerability Description
music-metadata is a metadata parser for audio and video media files. In the public development revision introduced after 11.14.0, a development-branch regression in the MP4 stsd sample-description parser allows an attacker-controlled sample-entry size of zero to prevent the StsdAtom.get cursor from advancing while an attacker-controlled entry_count keeps the synchronous loop running. A crafted MP4-family input can block the Node.js event loop and grow the sample-description table until the process is terminated or exhausts memory. The vulnerable change was present on the public master branch but was not included in music-metadata 11.14.0 or any earlier npm release, and version 11.16.0 contains the fix. This issue is fixed in version 11.16.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未加控制的资源消耗(资源穷尽)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Borewit music-metadata < 11.16.0 -

II. Public POCs for CVE-2026-107391

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107391

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107391 (2)

Other References for CVE-2026-107391 (2)

Same Patch Batch · Borewit · 2026-10-08 · 6 CVEs total

CVE-2026-107387 6.2 MEDIUM music-metadata: Uncontrolled memory allocation in APEv2 parser
CVE-2026-107388 6.2 MEDIUM music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion
CVE-2026-107390 6.2 MEDIUM music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length
CVE-2026-107389 6.2 MEDIUM music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process
CVE-2026-107392 6.2 MEDIUM music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-3

IV. Related Vulnerabilities

V. Comments for CVE-2026-107391

No comments yet


Leave a comment