CVE-2026-32889Disclosure(tinytag / tinytag)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

tinytag is a Python library for reading audio file metadata. Version 2.2.0 allows an attacker who can supply MP3 files for parsing to trigger a non-terminating loop while the library parses an ID3v2 SYLT (synchronized lyrics) frame. In server-side deployments that automatically parse attacker-supplied files, a single 498-byte MP3 can cause the parsing operation to stop making progress and remain busy until the worker or process is terminated. The root cause is that _parse_synced_lyrics assumes _find_string_end_pos always returns a position greater than the current offset. That assumption is false when no string terminator is present in the remaining frame content. This issue has been fixed in version 2.2.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-835

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tinytag

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
tinytag

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-20: 2Technical Details · 2026-03-20: 203-20
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32889 Infinite Loop in tinytag Python Library 2.2.0 via Malformed MP3 ID3v2 SYLT Frame https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32889

    Post summary

    CVE-2026-32889 is a disclosed vulnerability that causes an infinite loop in tinytag Python Library 2.2.0 through a malformed MP3 ID3v2 SYLT frame, as listed on vulmon.com.

    0000064
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32889 tinytag is a Python library for reading audio file metadata. Version 2.2.0 allows an attacker who can supply MP3 files for parsing to trigger a non-terminating loop w… https://www.cve.org/CVERecord?id=CVE-2026-32889

    Post summary

    The post notes a denial-of-service issue in tinytag 2.2.0 triggered by malicious MP3 files, but does not discuss PoC, exploits, active use, patches, or misinformation.

    0000062
    56.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptinytagtinytag2.2.0python-

Explore more