CVE-2026-32889 is a denial-of-service vulnerability affecting the tinytag Python library (versions prior to 2.2.1), which is used for reading audio file metadata. An attacker can trigger a non-terminating loop by supplying a specially crafted MP3 file containing a malicious ID3v2 SYLT frame, causing server-side parsing operations to become unresponsive. This vulnerability has a CVSS v3.1 score of 6.5 (Medium) and allows an unauthenticated attacker to achieve a high impact on availability with low attack complexity. There is currently no evidence of active exploitation, nor are there any public exploit modules or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.0CPE matchmatch criteria | cpe:2.3:a:tinytag:tinytag:2.2.0:*:*:*:*:python:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.