Junglewise Threat Intelligence

CVE-2026-32256: music-metadata infinite loop in ASF parser

CVE-2026-32256 · Severity: low · CVSS 3.1 · Published 2026-03-17

Vendors: npm.

Executive brief

music-metadata is a widely-used Node.js library (2.2M weekly downloads) that parses audio file metadata from various formats including ASF/WMA. A maliciously crafted ASF file can trigger an infinite loop in the parser, causing any application using the parseFile() or parseBuffer() methods to hang indefinitely. This can lead to denial of service where legitimate audio processing tasks freeze permanently.

Technical details

The vulnerability is an infinite loop in the ASF parser's parseExtensionObject() function (lib/asf/AsfParser.ts:112-158). When a sub-object within the ASF Header Extension Object has objectSize = 0, the parser calculates remaining = 0 - 24 = -24, then calls tokenizer.ignore(-24) to move backward, but the loop counter (extensionSize) is not decremented, so the while(extensionSize > 0) condition never exits. The root cause is that strtok3's AbstractTokenizer.ignore() accepts negative values without validation. The parseFile() and parseBuffer() methods are affected and will hang when processing a maliciously crafted 100-byte ASF file, while parseStream() is unaffected because it uses a different ignore() implementation that throws a RangeError. The vulnerability has been fixed in version 11.12.3.

Affected products

  • Borewit music-metadata <11.12.3

Timeline

  • 2026-03-17: disclosed: Vulnerability published on GitHub
  • 2026-03-17: patched: Fixed in version 11.12.3

References