PatchSiren cyber security CVE debrief
CVE-2026-107390 Borewit CVE debrief
CVE-2026-107390 is a vulnerability in the music-metadata library that allows for memory exhaustion via an oversized extended atom length in MP4 files. This issue, fixed in version 11.16.0, can cause a denial of service (DoS) attack when parsing untrusted MP4-family media files. The vulnerability is a result of the library's MP4 parser accepting an attacker-controlled 64-bit extended atom size, converting it to a JavaScript Number, and using the resulting payload length for atom-specific readToken calls before proving that the atom fits within its parent or the available input. A tiny MP4-family file can route an oversized length into payload parsing for atoms including mvhd, stsd,
- Vendor
- Borewit
- Product
- music-metadata
- CVSS
- MEDIUM 6.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-09
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-09
Who should care
Developers and administrators of applications that parse MP4 files using the music-metadata library, especially those handling large files or in resource-constrained environments, should be aware of this vulnerability and take steps to mitigate it.
Why it matters
CVE-2026-107390 is a medium-severity vulnerability in the music-metadata library that can lead to memory exhaustion and denial of service (DoS) attacks when parsing untrusted MP4 files. Developers and administrators should prioritize upgrading to version 11.16.0 or later and implementing additional security measures to validate and sanitize MP4 file inputs.
- Potential denial of service (DoS) attacks
- Increased resource usage when parsing malicious MP4 files
- Possible performance degradation or crashes
Technical summary
The music-metadata library, prior to version 11.16.0, is vulnerable to memory exhaustion attacks when parsing MP4 files with oversized extended atom lengths. This can lead to a denial of service (DoS) condition in applications that parse untrusted MP4-family media files. The vulnerability is caused by the library's MP4 parser not properly validating the extended atom length, allowing an attacker to cause a denial of service (DoS) attack. The fixed version, 11.16.0, addresses this issue by properly validating the extended atom length.
Defensive priority
Medium priority for applications parsing untrusted MP4 media, especially those handling large files or in resource-constrained environments.
Recommended defensive actions
- Upgrade to music-metadata version 11.16.0 or later
- Validate and sanitize MP4 file inputs
- Implement resource limits for MP4 parsing
- Monitor for unusual resource usage when parsing MP4 files
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and source item provide details on the vulnerability, its impact, and the fixed version. However, there is limited information on potential exploits or victim organizations. The vulnerability was introduced due to the library's MP4 parser not properly validating the extended atom length, allowing an attacker to cause a denial of service (DoS) attack. The fixed version, 11.16.0, addresses this issue by properly validating the extended atom length. Defenders should verify that their applications are using the fixed
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107390 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107390
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107390 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107390
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107390.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/Borewit/music-metadata/security/advisories/GHSA-qc8q-pw95-mq6c
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/Borewit/music-metadata/pull/2746
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/Borewit/music-metadata/commit/0f19ad66d71889b1c5f3ba84d4824f079ac4c005
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/Borewit/music-metadata/releases/tag/v11.16.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.