
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32889 is a denial-of-service vulnerability in tinytag, a Python library for reading audio file metadata, caused by a non-terminating loop when parsing malformed ID3v2 SYLT (synchronized lyrics) frames in MP3 files. It affects tinytag version 2.2.0 exclusively — the SYLT parsing feature was introduced in that release and is absent in 2.1.2 and earlier. The vulnerability was published on March 19, 2026, and fixed in version 2.2.1. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).
The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop). The _parse_synced_lyrics function incorrectly assumes that _find_string_end_pos always returns a position strictly greater than the current offset. When a SYLT frame's content lacks a null string terminator, content.find(b'\x00', start_pos) returns -1, causing _find_string_end_pos to return 0. This resets the loop's offset variable to 0, making the while offset < content_length condition permanently true and halting forward progress. The same flaw affects both ISO-8859-1/UTF-8 (single-byte) and UTF-16 (double-byte) encodings. The vulnerable call path is: TinyTag.get() → _load() → _parse_id3v2() → _parse_frame() for SYLT/SLT → _parse_synced_lyrics() → _find_string_end_pos(). A self-contained 498-byte crafted MP3 is sufficient to trigger the condition (GitHub Advisory, Patch Commit).
Successful exploitation causes the tinytag parsing worker or process to enter an infinite loop, consuming CPU indefinitely until externally terminated. In server-side deployments that automatically parse user-supplied audio files (e.g., media upload or metadata extraction services), a single malicious 498-byte MP3 file can tie up a worker process, degrading or denying service to other users. There is no confidentiality or integrity impact; the vulnerability is purely an availability issue (GitHub Advisory, Red Hat Bugzilla).
A proof-of-concept (PoC) Python script is publicly available in the GitHub security advisory, demonstrating construction of a malicious MP3 and triggering the infinite loop via TinyTag.get() with a 10-second timeout to confirm non-termination. No user privileges are required, though user interaction (file submission) is needed in typical deployment scenarios. The EPSS score is approximately 0.043% (0.000430), indicating a low probability of exploitation in the wild within 30 days. There is no evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time (GitHub Advisory).
\x00) string terminator in the lyrics data. A 498-byte file is sufficient.TinyTag.get() on the file, _parse_synced_lyrics enters a non-terminating loop, consuming 100% CPU on the worker thread/process.Upgrade tinytag to version 2.2.1 or later, which addresses the root cause via two commits: 5cd3215 ensures _find_string_end_pos never returns a value less than start_pos, and 44e4963 adds a bounds check to bail out if the SYLT offset exceeds content length. For systems unable to patch immediately, implement parsing timeouts, process isolation (e.g., sandboxed containers with CPU/time limits), and restrict or validate MP3 file uploads before passing them to tinytag (GitHub Advisory, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."