music-metadata, EBML Parser Memory Exhaustion, CVE-2026-107389 (Moderate) -DC-Oct2026-2957

Listen to this Post

The vulnerability resides within the Matroska/WebM EBML parser component of the library, which decodes variable-length integer (VINT) element lengths derived from untrusted media inputs without validating them against container boundaries or available input size. When a crafted .webm, .mkv, or .mka file specifies an inflated leaf length, the parser directly assigns this value to string and Uint8Array memory allocation routines. Consequently, a tiny malformed file can trigger massive memory reservations leading to denial of service, or force an uncatchable V8 fatal process abort with exit code 133 when sizes approach extreme limits like 32 GiB.

DailyCVE Form:

Platform: Node.js
Version: 11.15.0
Vulnerability : Memory Exhaustion
Severity: Moderate
date: 2026-03-24

Prediction: 2026-03-25

What Undercode Say

The underlying flaw stems from trusting unvalidated variable-length integer fields in media parsing. Without bounds checking against the physical input stream or parental container boundaries, untrusted numbers drive memory allocation sinks directly.

Analytics

npm install [email protected]
node -e "import('music-metadata').then(m => m.parseBuffer(Uint8Array.from([0x1a,0x45,0xdf,0xa3,0x8a,0x42,0x82,0x01,0xff,0xff,0xff,0xff,0xff,0xff,0xff]), {mimeType: 'video/webm'}))"
import { parseBuffer } from 'music-metadata';
const payload = Uint8Array.from([
0x1a, 0x45, 0xdf, 0xa3, 0x8a,
0x42, 0x82,
0x01, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff
]);
await parseBuffer(payload, { mimeType: 'video/webm' });

Exploit: (Educational Purposes!)

Attackers construct malicious Matroska/WebM files by supplying an oversized VINT length header inside leaf nodes such as `docType` or ebmlReadVersion. When parsed via entry points like `parseBuffer` or parseFile, the parser attempts to allocate hundreds of megabytes or gigabytes based on the fake length descriptor, causing immediate resource exhaustion or V8 heap crashes that evade try-catch blocks.

Protection: from this CVE

Upgrade `music-metadata` to version 11.16.0 or higher, which incorporates PR 2735 validation logic to safely check leaf lengths against container bounds and remaining file data prior to allocation.

Impact

Successful exploitation leads to application availability degradation or complete denial of service via memory exhaustion and uncatchable V8 process aborts (Exit Code 133). Confidentiality and integrity remain unaffected.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top