CVE-2026-32256 | Borewit music-metadata up to 11.12.2 ASF Parser lib/asf/AsfParser.ts parseExtensionObject infinite loop (GHSA-v6c2-xwv6-8xf7)
A vulnerability, which was classified as problematic, has been found in Borewit music-metadata up to 11.12.2. This affects the function parseExtensionObject in the library lib/asf/AsfParser.ts of the component ASF Parser. The manipulation leads to infinite loop.
This vulnerability is referenced as CVE-2026-32256. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.