Search CVE reports


Toggle filters

1 – 10 of 13 results


CVE-2026-53540

Medium priority
Needs evaluation

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned...

1 affected package

python-multipart

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-multipart Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-53539

Medium priority
Needs evaluation

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire...

1 affected package

python-multipart

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-multipart Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-53538

Medium priority
Needs evaluation

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern...

1 affected package

python-multipart

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-multipart Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-53537

Medium priority
Needs evaluation

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987...

1 affected package

python-multipart

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-multipart Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-42561

Medium priority
Needs evaluation

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously...

1 affected package

python-multipart

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-multipart Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-8162

Medium priority
Needs evaluation

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a Content-Disposition header whose filename* parameter contains a...

1 affected package

node-multiparty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-multiparty Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-8161

Medium priority
Needs evaluation

multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/form-data request with a field name that collides with an inherited Object.prototype property such...

1 affected package

node-multiparty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-multiparty Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-8159

Medium priority
Needs evaluation

multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Content-Disposition filename parameter parser. A crafted multipart upload with a long header value can cause regex...

1 affected package

node-multiparty

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
node-multiparty Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-40347

Medium priority
Needs evaluation

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to...

1 affected package

python-multipart

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
python-multipart Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-28356

Medium priority
Fixed

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can...

1 affected package

multipart

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
multipart Fixed Not in release Not in release
Show less packages