{"id":"CVE-2026-42561","aliases":["GHSA-pp6c-gr5w-3c5g","PYSEC-2026-3039"],"title":"python-multipart has Denial of Service via unbounded multipart part headers","summary":"python-multipart has Denial of Service via unbounded multipart part headers","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"python-multipart","product":"python-multipart","ecosystem":"pip","affected":["python-multipart < 0.0.27"],"patched":["python-multipart 0.0.27"],"published":"2026-05-06","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:47.215892833Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-pp6c-gr5w-3c5g","references":[{"url":"https://github.com/Kludex/python-multipart/security/advisories/GHSA-pp6c-gr5w-3c5g"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42561"},{"url":"https://github.com/Kludex/python-multipart"}],"tags":["osv","pip"],"epss":0.0074,"epssPercentile":0.53154,"ingestedAt":"2026-07-13T18:58:01.583Z","slug":"CVE-2026-42561","body":"## Overview\n\n### Summary\n\n`python-multipart` has a denial of service vulnerability in multipart part header parsing. When parsing `multipart/form-data`, `MultipartParser` previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request rejection or completion.\n\n### Impact\n\nApplications that parse attacker-controlled `multipart/form-data` with affected versions of `python-multipart` can experience CPU exhaustion. ASGI applications using Starlette, FastAPI, or other frameworks that invoke `python-multipart` may have worker or event-loop delays while processing malicious upload requests.\n\n### Details\n\nThe affected parser states are `HEADER_FIELD_START`, `HEADER_FIELD`, `HEADER_VALUE_START`, `HEADER_VALUE`, and `HEADER_VALUE_ALMOST_DONE`. The issue can be triggered by:\n\n- A multipart part with an oversized individual header value.\n- A multipart part with many repeated header lines or an unterminated header block.\n\nBoth variants are addressed by enforcing default parser limits for maximum header count and maximum header size.\n\n### Mitigation\n\nUpgrade to `python-multipart` `0.0.27` or later.\n\nIf upgrading is not immediately possible, reduce exposure by enforcing request body size limits at the server, proxy, or framework layer. This is only a mitigation; affected versions of `python-multipart` still parse multipart part headers without the default header count and header size limits.\n\n## Affected packages\n\n- `python-multipart < 0.0.27`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `python-multipart 0.0.27`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}