High severityNVD Advisory· Published Mar 18, 2026· Updated Mar 18, 2026
music-metadata has an infinite loop vulnerability in ASF parser
CVE-2026-32256
Description
music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF parser (parseExtensionObject() in lib/asf/AsfParser.ts:112-158) enters an infinite loop when a sub-object inside the ASF Header Extension Object has objectSize = 0. Version 11.12.3 fixes the issue.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
music-metadatanpm | < 11.12.3 | 11.12.3 |
Affected products
1- Range: < 11.12.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-v6c2-xwv6-8xf7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-32256ghsaADVISORY
- github.com/Borewit/music-metadata/releases/tag/v11.12.3ghsax_refsource_MISCWEB
- github.com/Borewit/music-metadata/security/advisories/GHSA-v6c2-xwv6-8xf7ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.