LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-32889

tinytag · tinytag

Published
CVSS6.5
Severitymedium
WeaknessCWE-835
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Description

tinytag is a Python library for reading audio file metadata. Version 2.2.0 allows an attacker who can supply MP3 files for parsing to trigger a non-terminating loop while the library parses an ID3v2 SYLT (synchronized lyrics) frame. In server-side deployments that automatically parse attacker-supplied files, a single 498-byte MP3 can cause the parsing operation to stop making progress and remain busy until the worker or process is terminated. The root cause is that _parse_synced_lyrics assumes _find_string_end_pos always returns a position greater than the current offset. That assumption is false when no string terminator is present in the remaining frame content. This issue has been fixed i

References

← Back to the CVE Tracker

Our coverage of CVE-2026-32889

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-32889.