CVE-2026-32889 | tinytag up to 2.2.0 _parse_synced_lyrics infinite loop (GHSA-f4rq-2259-hv29)
A vulnerability, which was classified as problematic, has been found in tinytag up to 2.2.0. Affected is the function _parse_synced_lyrics. The manipulation leads to infinite loop.
This vulnerability is traded as CVE-2026-32889. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.