CVE-2026-107390
music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length
music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the MP4 parser accepts an attacker-controlled 64-bit extended atom size, converts it to a JavaScript Number, and uses the resulting payload length for atom-specific readToken calls before proving that the atom fits within its parent or the available input. A tiny MP4-family file can route an oversized length into payload parsing for atoms including mvhd, stsd, stsz, and date, causing a large allocation attempt or process failure before end-of-input validation. Applications that parse untrusted MP4-family media can therefore be denied service. This issue is fixed in version 11.16.0.
| CWE | CWE-789 |
| Vendor | borewit |
| Product | music-metadata |
| Published | Oct 8, 2026 |
Get instant alerts for borewit music-metadata
Be the first to know when new medium vulnerabilities affecting borewit music-metadata are published โ delivered to Slack, Telegram or Discord.
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H