Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-53v6-4h7p-p4gj | music-metadata: Uncontrolled memory allocation in APEv2 parser |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Borewit
Borewit music-metadata |
|
| Vendors & Products |
Borewit
Borewit music-metadata |
Thu, 08 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the APEv2 parser reads an attacker-controlled tag-item size and allocates a Uint8Array for a binary item before proving that the declared item fits in the remaining tag or file data. A small crafted APE file can therefore trigger a disproportionate allocation, including through cover-art items, and repeated or concurrent parsing can exhaust process memory. The demonstrated impact is availability loss only. This issue is fixed in version 11.16.0. | |
| Title | music-metadata: Uncontrolled memory allocation in APEv2 parser | |
| Weaknesses | CWE-789 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-08T19:32:13.101Z
Reserved: 2026-10-07T21:07:54.988Z
Link: CVE-2026-107387
Updated: 2026-10-08T19:32:09.095Z
Status : Awaiting Analysis
Published: 2026-10-08T19:17:01.517
Modified: 2026-10-08T20:46:35.260
Link: CVE-2026-107387
No data.
OpenCVE Enrichment
Updated: 2026-10-08T20:30:18Z
Github GHSA