Memory Exhaustion Vulnerability in Music-Metadata by Borewit
CVE-2026-107387

6.2MEDIUM

Key Information:

Vendor

Borewit

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107387?

The music-metadata library is susceptible to a memory exhaustion issue caused by its APEv2 parser. Versions prior to 11.16.0 do not adequately validate the declared size of tag items when processing crafted APE files. An attacker can exploit this flaw by supplying a specially designed APE file that triggers excessive memory allocation during parsing. This vulnerability may lead to availability loss due to memory exhaustion, potentially affecting the performance of applications utilizing this library. Users are advised to upgrade to version 11.16.0 or later to mitigate this risk.

Affected Version(s)

music-metadata < 11.16.0

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.