CVE-2026-107392

Source
https://cve.org/CVERecord?id=CVE-2026-107392
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107392.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107392
Aliases
Downstream
Published
2026-10-08T19:13:06Z
Modified
2026-10-10T02:47:27Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of CVE-2026-32256)
Details

music-metadata is a metadata parser for audio and video media files. Prior to 11.15.0, the DSF parser handles an unrecognized chunk by calling tokenizer.ignore without awaiting the returned promise and without first rejecting a chunk size smaller than the 12-byte chunk header. A crafted DSF input can produce a negative ignore length; with strtok3 10.3.5 or later, the resulting RangeError is detached from the parseBuffer promise and becomes an unhandled rejection under Node.js default behavior. The parse call can appear to resolve before the process crashes, bypassing per-parse try/catch handling. The demonstrated impact is availability loss only and requires the DSF parsing path. This issue is fixed in version 11.15.0.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-248",
        "CWE-400"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107392.json"
}
References

Affected packages

Git / github.com/borewit/music-metadata

Affected ranges

Type
GIT
Repo
https://github.com/borewit/music-metadata
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "11.15.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.0.2
0.1.0
0.1.1
0.1.2
0.6.2
0.8.4
Browser-0.*
Browser-0.4.3
Other
remove
v0.*
v0.10.1
v0.10.2
v0.10.3
v0.11.0
v0.11.1
v0.11.2
v0.11.3
v0.11.4
v0.11.5
v0.3.4
v0.3.5
v0.3.6
v0.4.0
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.4.5
v0.4.6
v0.5.0
v0.5.1
v0.5.2
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.6.6
v0.7.0
v0.7.1
v0.7.10
v0.7.11
v0.7.12
v0.7.13
v0.7.14
v0.7.15
v0.7.17
v0.7.2
v0.7.3
v0.7.5
v0.7.6
v0.7.7
v0.7.8
v0.8.0
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.8.5
v0.8.6
v0.8.7
v0.9.0
v0.9.1
v0.9.10
v0.9.11
v0.9.12
v0.9.13
v0.9.14
v0.9.15
v0.9.2
v0.9.3
v0.9.4
v0.9.5
v0.9.6
v0.9.7
v0.9.8
v1.*
v1.0.0
v1.0.1
v1.1.0
v10.*
v10.0.0
v10.1.0
v10.2.0
v10.3.0
v10.3.1
v10.4.0
v10.5.0
v10.5.1
v10.6.0
v10.6.1
v10.6.2
v10.6.4
v10.6.5
v10.7.0
v10.7.1
v10.8.0
v10.8.1
v10.8.2
v10.8.3
v10.9.0
v10.9.1
v11.*
v11.0.0
v11.0.1
v11.0.2
v11.0.3
v11.0.4
v11.0.5
v11.1.0
v11.1.1
v11.10.0
v11.10.1
v11.10.2
v11.10.3
v11.10.4
v11.10.5
v11.10.6
v11.11.0
v11.11.1
v11.11.2
v11.12.0
v11.12.1
v11.12.2
v11.12.3
v11.14.0
v11.2.0
v11.2.1
v11.2.2
v11.2.3
v11.3.0
v11.4.0
v11.5.0
v11.6.0
v11.6.1
v11.7.0
v11.7.1
v11.7.2
v11.7.3
v11.8.0
v11.8.1
v11.8.2
v11.8.3
v11.9.0
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.1.0
v2.2.0
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.4.0
v2.4.1
v2.4.2
v2.4.3
v2.5.0
v2.6.0
v2.6.1
v2.6.2
v2.8.0
v2.8.1
v3.*
v3.0.0
v3.1.0
v3.1.1
v3.1.2
v3.1.3
v3.1.5
v3.1.6
v3.2.0
v3.2.1
v3.2.2
v3.2.3
v3.2.4
v3.3.0
v3.3.1
v3.3.2
v3.4.0
v3.4.1
v3.5.0
v3.5.1
v3.5.2
v3.5.3
v3.5.4
v3.6.0
v3.6.1
v3.7.0
v3.8.0
v4.*
v4.0.0
v4.0.1
v4.1.0
v4.1.1
v4.1.2
v4.2.0
v4.2.1
v4.2.2-beta
v4.2.3
v4.2.4
v4.3.0
v4.3.1
v4.4.0
v4.5.1
v4.5.2
v4.5.3
v4.6.0
v4.7.0
v4.8.0
v4.8.1
v4.8.2
v4.8.3
v4.8.4
v4.9.0
v4.9.1
v4.9.2
v5.*
v5.0.0
v5.0.2
v5.1.0
v5.2.0
v5.3.0
v5.3.1
v5.3.2
v5.4.0
v5.4.1
v5.4.2
v5.4.3
v6.*
v6.0.0
v6.0.1
v6.1.0
v6.1.1
v6.1.2
v6.2.0
v6.3.0
v6.3.1
v6.3.2
v6.3.3
v6.3.4
v6.3.5
v6.3.6
v6.3.7
v6.4.0
v7.*
v7.0.0
v7.0.1
v7.0.2
v7.1.0
v7.1.1
v7.1.2
v7.10.0
v7.11.0
v7.11.1
v7.11.10
v7.11.2
v7.11.3
v7.11.4
v7.11.5
v7.11.6
v7.11.7
v7.11.8
v7.12.0
v7.12.1
v7.12.2
v7.12.3
v7.12.4
v7.12.5
v7.12.6
v7.2.0
v7.3.0
v7.4.0
v7.4.1
v7.5.0
v7.5.1
v7.5.2
v7.5.3
v7.6.0
v7.6.1
v7.6.2
v7.6.3
v7.6.4
v7.6.5
v7.6.6
v7.6.7
v7.6.8
v7.7.0
v7.8.0
v7.8.3
v7.8.4
v7.8.5
v7.8.6
v7.8.7
v7.8.8
v8.*
v8.0.0
v8.0.1
v8.1.0
v8.1.1
v8.1.2
v8.1.3
v8.1.4
v8.1.5
v8.3.0
v9.*
v9.0.0
v9.0.1
v9.0.2
v9.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107392.json"