PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107390 Borewit CVE debrief

CVE-2026-107390 is a vulnerability in the music-metadata library that allows for memory exhaustion via an oversized extended atom length in MP4 files. This issue, fixed in version 11.16.0, can cause a denial of service (DoS) attack when parsing untrusted MP4-family media files. The vulnerability is a result of the library's MP4 parser accepting an attacker-controlled 64-bit extended atom size, converting it to a JavaScript Number, and using the resulting payload length for atom-specific readToken calls before proving that the atom fits within its parent or the available input. A tiny MP4-family file can route an oversized length into payload parsing for atoms including mvhd, stsd,

Vendor
Borewit
Product
music-metadata
CVSS
MEDIUM 6.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-09
Advisory published
2026-10-08
Advisory updated
2026-10-09

Who should care

Developers and administrators of applications that parse MP4 files using the music-metadata library, especially those handling large files or in resource-constrained environments, should be aware of this vulnerability and take steps to mitigate it.

Why it matters

CVE-2026-107390 is a medium-severity vulnerability in the music-metadata library that can lead to memory exhaustion and denial of service (DoS) attacks when parsing untrusted MP4 files. Developers and administrators should prioritize upgrading to version 11.16.0 or later and implementing additional security measures to validate and sanitize MP4 file inputs.

  • Potential denial of service (DoS) attacks
  • Increased resource usage when parsing malicious MP4 files
  • Possible performance degradation or crashes

Technical summary

The music-metadata library, prior to version 11.16.0, is vulnerable to memory exhaustion attacks when parsing MP4 files with oversized extended atom lengths. This can lead to a denial of service (DoS) condition in applications that parse untrusted MP4-family media files. The vulnerability is caused by the library's MP4 parser not properly validating the extended atom length, allowing an attacker to cause a denial of service (DoS) attack. The fixed version, 11.16.0, addresses this issue by properly validating the extended atom length.

Defensive priority

Medium priority for applications parsing untrusted MP4 media, especially those handling large files or in resource-constrained environments.

Recommended defensive actions

  • Upgrade to music-metadata version 11.16.0 or later
  • Validate and sanitize MP4 file inputs
  • Implement resource limits for MP4 parsing
  • Monitor for unusual resource usage when parsing MP4 files
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and source item provide details on the vulnerability, its impact, and the fixed version. However, there is limited information on potential exploits or victim organizations. The vulnerability was introduced due to the library's MP4 parser not properly validating the extended atom length, allowing an attacker to cause a denial of service (DoS) attack. The fixed version, 11.16.0, addresses this issue by properly validating the extended atom length. Defenders should verify that their applications are using the fixed

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107390 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107390

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107390 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107390

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • music-metadata: MP4 parser allows memory exhaustion via oversized extended atom length

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107390.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Borewit/music-metadata/security/advisories/GHSA-qc8q-pw95-mq6c

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Borewit/music-metadata/pull/2746

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Borewit/music-metadata/commit/0f19ad66d71889b1c5f3ba84d4824f079ac4c005

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Borewit/music-metadata/releases/tag/v11.16.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.