CVE-2026-107392

LOWCVSS 6.2 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore without awaiting the returned promise and without first rejecting a chunk size smaller than the 12-byte chunk header. A crafted DSF input can produce a negative ignore length; with strtok3 10.3.5 or later, the resulting RangeError is detached from the parseBuffer promise and becomes an unhandled rejection under Node.js default behavior. The parse call can appear to resolve before the process crashes, bypassing per-parse try/catch handling. The demonstrated impact is availability loss only and requires the DSF parsing path. This issue is fixed in version 11.15.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-248CWE-400

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-10-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-10-08: 1Mentions · 2026-10-09: 110-0810-09
Referenced assets2 URLs
Full discourse2 posts
  • DailyCVE@dailycve

    🟠 music-metadata, Uncatchable Process Crash, #CVE-2026-107392 (Moderate) -DC-Oct2026-2954 https://dailycve.com/music-metadata-uncatchable-process-crash-cve-2026-107392-moderate-dc-oct2026-2954/

    0000018
    239 followersView on X
  • CVE@CVEnew

    CVE-2026-107392 music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore with… https://www.cve.org/CVERecord?id=CVE-2026-107392

    00000677
    58.1K followersView on X

Explore more