Vulnerability in MP4 StsdAtom Parser Affects Music Metadata by Borewit
CVE-2026-107391
6.2MEDIUM
What is CVE-2026-107391?
A vulnerability in the music-metadata library's MP4 sample-description parser allows crafted MP4 input files to manipulate the event loop, potentially leading to memory exhaustion or process termination. This issue arises from a regression that enables an attacker to control sample-entry sizes. The problem persists in versions after 11.14.0 and can be mitigated by upgrading to version 11.16.0, where the vulnerability has been addressed.
Affected Version(s)
music-metadata < 11.16.0
