music-metadata is a metadata parser for audio and video media files. Prior to 11.16.0, the ID3v2 parser trusts the syncsafe tag-size field and allocates the complete tag body before checking whether the input contains the declared bytes. A truncated file containing only an ID3v2 header can request an allocation approaching 268 MiB; the allocation succeeds, the subsequent read reaches end of stream, the EndOfStreamError is caught internally, and the caller receives a normal metadata object. This issue is fixed in version 11.16.0.
https://github.com/Borewit/music-metadata/security/advisories/GHSA-jjpr-9cvf-cq55
https://github.com/Borewit/music-metadata/releases/tag/v11.16.0
https://github.com/Borewit/music-metadata/pull/2743
https://github.com/Borewit/music-metadata/commit/b033db675b913a9dba1d29135ec3c10eae7095a7