Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107392— music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-32256)

Quick assessment

Affected
Borewit music-metadata
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

music-metadata 是一个用于解析音频和视频媒体文件元数据的库。在版本 11.15.0 之前,DSF 解析器在处理未识别的数据块(chunk)时,会调用 tokenizer.ignore,但未等待其返回的 Promise,也未先拒绝小于 12 字节(即 DSF 数据块头长度)的数据块大小。通过构造恶意的 DSF 输入,可以产生负数的忽略长度(ignore length);当使用 strtok3 10.3.5 或更高版本时,由此引发的 RangeError 会与 parseBuffer Promise 脱离

CVSS 6.2 · Medium

Possible ATT&CK Techniques 1 AI

T1496 · Resource Hijacking

Affected Version Matrix 1

VendorProduct Version RangeStatus
Borewit music-metadata < 11.15.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107392

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-32256)
Source: CVE Program / CVE List V5
Vulnerability Description
music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore without awaiting the returned promise and without first rejecting a chunk size smaller than the 12-byte chunk header. A crafted DSF input can produce a negative ignore length; with strtok3 10.3.5 or later, the resulting RangeError is detached from the parseBuffer promise and becomes an unhandled rejection under Node.js default behavior. The parse call can appear to resolve before the process crashes, bypassing per-parse try/catch handling. The demonstrated impact is availability loss only and requires the DSF parsing path. This issue is fixed in version 11.15.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
未捕获的异常
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Borewit music-metadata < 11.15.0 -

II. Public POCs for CVE-2026-107392

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107392

请登录查看更多情报信息。

Other References for CVE-2026-107392 (4)

Same Patch Batch · Borewit · 2026-10-08 · 6 CVEs total

CVE-2026-107387 6.2 MEDIUM music-metadata: Uncontrolled memory allocation in APEv2 parser
CVE-2026-107388 6.2 MEDIUM music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion
CVE-2026-107390 6.2 MEDIUM music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length
CVE-2026-107389 6.2 MEDIUM music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process
CVE-2026-107391 6.2 MEDIUM music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — u

IV. Related Vulnerabilities

V. Comments for CVE-2026-107392

No comments yet


Leave a comment