CVE-2026-107390

Published: Ott 08, 2026 Last Modified: Ott 09, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 6,2
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high

Description

AI Translation Available

music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the MP4 parser accepts an attacker-controlled 64-bit extended atom size, converts it to a JavaScript Number, and uses the resulting payload length for atom-specific readToken calls before proving that the atom fits within its parent or the available input. A tiny MP4-family file can route an oversized length into payload parsing for atoms including mvhd, stsd, stsz, and date, causing a large allocation attempt or process failure before end-of-input validation. Applications that parse untrusted MP4-family media can therefore be denied service. This issue is fixed in version 11.16.0.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0013
Percentile
0,0th
Updated

EPSS Score Trend (Last 3 Days)

789

Memory Allocation with Excessive Size Value

Draft
Common Consequences
Security Scopes Affected:
Availability
Potential Impacts:
Dos: Resource Consumption (Memory)
Applicable Platforms
Languages: C, C++, Not Language-Specific
View CWE Details
https://github.com/Borewit/music-metadata/security/advisories/GHSA-qc8q-pw95-mq…
https://github.com/Borewit/music-metadata/commit/0f19ad66d71889b1c5f3ba84d4824f…
https://github.com/Borewit/music-metadata/pull/2746
https://github.com/Borewit/music-metadata/releases/tag/v11.16.0
https://github.com/Borewit/music-metadata/security/advisories/GHSA-qc8q-pw95-mq…