CVE-2026-32889: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-32889 is a denial-of-service vulnerability in tinytag, a Python library for reading audio file metadata, caused by a non-terminating loop when parsing malformed ID3v2 SYLT (synchronized lyrics) frames in MP3 files. It affects tinytag version 2.2.0 exclusively — the SYLT parsing feature was introduced in that release and is absent in 2.1.2 and earlier. The vulnerability was published on March 19, 2026, and fixed in version 2.2.1. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop). The _parse_synced_lyrics function incorrectly assumes that _find_string_end_pos always returns a position strictly greater than the current offset. When a SYLT frame's content lacks a null string terminator, content.find(b'\x00', start_pos) returns -1, causing _find_string_end_pos to return 0. This resets the loop's offset variable to 0, making the while offset < content_length condition permanently true and halting forward progress. The same flaw affects both ISO-8859-1/UTF-8 (single-byte) and UTF-16 (double-byte) encodings. The vulnerable call path is: TinyTag.get() → _load() → _parse_id3v2() → _parse_frame() for SYLT/SLT → _parse_synced_lyrics() → _find_string_end_pos(). A self-contained 498-byte crafted MP3 is sufficient to trigger the condition (GitHub Advisory, Patch Commit).

Impact

Successful exploitation causes the tinytag parsing worker or process to enter an infinite loop, consuming CPU indefinitely until externally terminated. In server-side deployments that automatically parse user-supplied audio files (e.g., media upload or metadata extraction services), a single malicious 498-byte MP3 file can tie up a worker process, degrading or denying service to other users. There is no confidentiality or integrity impact; the vulnerability is purely an availability issue (GitHub Advisory, Red Hat Bugzilla).

Exploitability

A proof-of-concept (PoC) Python script is publicly available in the GitHub security advisory, demonstrating construction of a malicious MP3 and triggering the infinite loop via TinyTag.get() with a 10-second timeout to confirm non-termination. No user privileges are required, though user interaction (file submission) is needed in typical deployment scenarios. The EPSS score is approximately 0.043% (0.000430), indicating a low probability of exploitation in the wild within 30 days. There is no evidence of active in-the-wild exploitation or CISA KEV catalog listing at this time (GitHub Advisory).

Exploitation steps

  1. Craft malicious MP3: Construct a minimal MP3 file containing an ID3v2.3 header with a SYLT frame whose payload uses ISO-8859-1 encoding and omits the required null byte (\x00) string terminator in the lyrics data. A 498-byte file is sufficient.
  2. Identify target: Locate a server-side application or API endpoint that accepts MP3 file uploads and uses tinytag 2.2.0 to extract metadata automatically.
  3. Submit the file: Upload or submit the crafted MP3 to the target service (e.g., via HTTP multipart form upload or API call).
  4. Trigger infinite loop: When the server calls TinyTag.get() on the file, _parse_synced_lyrics enters a non-terminating loop, consuming 100% CPU on the worker thread/process.
  5. Sustain DoS: Repeat submissions (or a single submission if the worker is not auto-restarted) to keep the service unavailable until the process is manually terminated or the server restarts the worker (GitHub Advisory).

Indicators of compromise

  • Process: Worker or process running tinytag metadata extraction consuming 100% CPU for an extended, abnormal duration without completing.
  • Logs: Application logs showing a metadata parsing request that never returns or times out, particularly for MP3 files with SYLT/SLT frame identifiers.
  • File System: Presence of small (~498-byte) MP3 files submitted by external users that contain ID3v2 SYLT frames with no null terminator in the lyrics payload.
  • Network: Repeated upload requests for unusually small MP3 files (≤500 bytes) to media processing endpoints, potentially from the same source IP (GitHub Advisory).

Mitigation and workarounds

Upgrade tinytag to version 2.2.1 or later, which addresses the root cause via two commits: 5cd3215 ensures _find_string_end_pos never returns a value less than start_pos, and 44e4963 adds a bounds check to bail out if the SYLT offset exceeds content length. For systems unable to patch immediately, implement parsing timeouts, process isolation (e.g., sandboxed containers with CPU/time limits), and restrict or validate MP3 file uploads before passing them to tinytag (GitHub Advisory, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management