All 7 CVE vulnerabilities found in music-metadata, with AI-generated Chinese analysis, references, and POCs.
Vendor: Borewit
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-107392 | music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-32256) CWE-248 | 6.2 | Medium | 2026-10-08 |
| CVE-2026-107391 | music-metadata: MP4 stsd sample-entry size==0 causes a synchronous infinite loop (DoS) — unreleased regression on master CWE-400 | 6.2 | Medium | 2026-10-08 |
| CVE-2026-107390 | music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length CWE-789 | 6.2 | Medium | 2026-10-08 |
| CVE-2026-107389 | music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort CWE-789 | 6.2 | Medium | 2026-10-08 |
| CVE-2026-107388 | music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS CWE-789 | 6.2 | Medium | 2026-10-08 |
| CVE-2026-107387 | music-metadata: Uncontrolled memory allocation in APEv2 parser CWE-789 | 6.2 | Medium | 2026-10-08 |
| CVE-2026-32256 | music-metadata has an infinite loop vulnerability in ASF parser CWE-835 | 7.5 | High | 2026-03-18 |
All 7 known CVE vulnerabilities affecting music-metadata with full Chinese analysis, references, and POCs where available.