Executive brief
tinytag is a Python library used to read metadata from audio files, such as song titles and lyrics. A vulnerability in version 2.2.0 allows a specially crafted MP3 file to cause the library to enter an infinite loop during processing. In a server environment that automatically processes user-uploaded audio, this can lead to a denial-of-service by exhausting system resources and hanging the application until it is manually restarted.
Technical details
A denial-of-service vulnerability exists in tinytag 2.2.0 due to an infinite loop in the ID3v2 SYLT frame parser. The root cause is located in the `_parse_synced_lyrics` function, which relies on `_find_string_end_pos` to return a position greater than the current offset. If a SYLT frame is missing a null terminator, `_find_string_end_pos` returns 0, causing the parser to reset its offset and loop indefinitely. An attacker can exploit this by providing a small (approx. 500-byte) malicious MP3 file to any application using the library to parse metadata. The issue is fixed in version 2.2.1 by ensuring the string end position is never smaller than the start position.
Affected products
- tinytag project tinytag 2.2.0
Timeline
- 2026-03-12: other: Vulnerability confirmed on main branch by reporter
- 2026-03-19: advisory: GitHub Security Advisory GHSA-f4rq-2259-hv29 published
- 2026-03-20: disclosed: CVE-2026-32889 published to NVD
References
- https://github.com/tinytag/tinytag/commit/44e496310f7ced8077e9087e3774acbaa324b18a
- https://github.com/tinytag/tinytag/commit/4d649b9c314ada8ff8a74e0469e9aadb3acb252a
- https://github.com/tinytag/tinytag/commit/5cd321521ff097e41724b601d7e3d7adc7e53402
- https://github.com/tinytag/tinytag/security/advisories/GHSA-f4rq-2259-hv29