{"id":"CVE-2024-53981","aliases":["GHSA-59g5-xgcq-4qw3","PYSEC-2026-1851"],"title":"Denial of service (DoS) via deformation `multipart/form-data` boundary","summary":"Denial of service (DoS) via deformation `multipart/form-data` boundary","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"python-multipart","product":"python-multipart","ecosystem":"pip","affected":["python-multipart < 0.0.18"],"patched":["python-multipart 0.0.18"],"published":"2024-12-02","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:21.270678783Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-59g5-xgcq-4qw3","references":[{"url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-59g5-xgcq-4qw3"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-53981"},{"url":"https://github.com/Kludex/python-multipart/commit/c4fe4d3cebc08c660e57dd709af1ffa7059b3177"},{"url":"https://github.com/Kludex/python-multipart"}],"tags":["osv","pip"],"epss":0.0064,"epssPercentile":0.48387,"ingestedAt":"2026-07-08T18:25:45.906Z","slug":"CVE-2024-53981","body":"## Overview\n\n### Summary\n\nWhen parsing form data, `python-multipart` skips line breaks (CR `\\r` or LF `\\n`) in front of the first boundary and any tailing bytes after the last boundary. This happens one byte at a time and emits a log event each time, which may cause excessive logging for certain inputs.\n\nAn attacker could abuse this by sending a malicious request with lots of data before the first or after the last boundary, causing high CPU load and stalling the processing thread for a significant amount of time. In case of ASGI application, this could stall the event loop and prevent other requests from being processed, resulting in a denial of service (DoS).\n\n### Impact\n\nApplications that use `python-multipart` to parse form data (or use frameworks that do so) are affected. \n\n### Original Report\n\nThis security issue was reported by:\n- GitHub security advisory in Starlette on October 30 by @Startr4ck\n- Email to `python-multipart` maintainer on October 3 by @mnqazi\n\n## Affected packages\n\n- `python-multipart < 0.0.18`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `python-multipart 0.0.18`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}