Infinite loop Affecting music-metadata package, versions <11.12.3


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-MUSICMETADATA-15680352
  • published18 Mar 2026
  • disclosed17 Mar 2026
  • creditByambadalai Sumiya

Introduced: 17 Mar 2026

NewCVE-2026-32256  (opens in a new tab)
CWE-835  (opens in a new tab)

How to fix?

Upgrade music-metadata to version 11.12.3 or higher.

Overview

music-metadata is a Music metadata parser for Node.js, supporting virtual any audio and tag format.

Affected versions of this package are vulnerable to Infinite loop through the parseExtensionObject process in the ASF parser when handling a sub-object with objectSize = 0. An attacker can cause the application to hang indefinitely by providing a specially crafted .asf file that triggers an infinite loop during parsing.

CVSS Base Scores

version 4.0
version 3.1