{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "0"
              },
              {
                "fixed": "11.16.0"
              }
            ],
            "source": [
              "AFFECTED_FIELD",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "163f013364ac9fc8dd0c3987433cd065a615af58"
            },
            {
              "fixed": "2d14dc1f7391a94235948a0b823155538f69b3df"
            },
            {
              "fixed": "9e995a31c9e5526057a63936cb83d9f8b02e0fcc"
            }
          ],
          "repo": "https://github.com/borewit/music-metadata",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-5gfj-9q3v-qfp3"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-789"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107389.json"
  },
  "details": "music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the Matroska and WebM EBML parser decodes an attacker-controlled VINT element length and uses it for string-token or Uint8Array allocation before confirming that the leaf fits within its parent or available input. Crafted WebM, MKV, or MKA inputs can cause disproportionate allocations, out-of-memory denial of service, or, for a demonstrated parseFile path on Node.js 26.7.0, an uncatchable V8 fatal abort. The exact failure mode depends on the tokenizer, parser API, and runtime, but the affected leaf-length validation flaw is shared and has availability impact only. This issue is fixed in version 11.16.0.",
  "id": "CVE-2026-107389",
  "modified": "2026-10-11T02:30:52.110627175Z",
  "published": "2026-10-08T19:05:23.816Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/Borewit/music-metadata/releases/tag/v11.16.0"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/Borewit/music-metadata/security/advisories/GHSA-5gfj-9q3v-qfp3"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107389.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107389"
    },
    {
      "type": "FIX",
      "url": "https://github.com/Borewit/music-metadata/commit/163f013364ac9fc8dd0c3987433cd065a615af58"
    },
    {
      "type": "FIX",
      "url": "https://github.com/Borewit/music-metadata/commit/2d14dc1f7391a94235948a0b823155538f69b3df"
    },
    {
      "type": "FIX",
      "url": "https://github.com/Borewit/music-metadata/pull/2735"
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "music-metadata: EBML parser trusts element lengths, allowing memory exhaustion or process abort"
}