---
id: CVE-2024-53981
aliases:
  - GHSA-59g5-xgcq-4qw3
  - PYSEC-2026-1851
title: Denial of service (DoS) via deformation `multipart/form-data` boundary
summary: Denial of service (DoS) via deformation `multipart/form-data` boundary
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: python-multipart
product: python-multipart
ecosystem: pip
affected:
  - python-multipart < 0.0.18
patched:
  - python-multipart 0.0.18
published: '2024-12-02'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:21.270678783Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-59g5-xgcq-4qw3'
references:
  - url: >-
      https://github.com/Kludex/python-multipart/security/advisories/GHSA-59g5-xgcq-4qw3
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-53981'
  - url: >-
      https://github.com/Kludex/python-multipart/commit/c4fe4d3cebc08c660e57dd709af1ffa7059b3177
  - url: 'https://github.com/Kludex/python-multipart'
tags:
  - osv
  - pip
epss: 0.0064
epssPercentile: 0.48458
ingestedAt: '2026-07-08T18:25:45.906Z'
---

## Overview

### Summary

When parsing form data, `python-multipart` skips line breaks (CR `\r` or LF `\n`) in front of the first boundary and any tailing bytes after the last boundary. This happens one byte at a time and emits a log event each time, which may cause excessive logging for certain inputs.

An attacker could abuse this by sending a malicious request with lots of data before the first or after the last boundary, causing high CPU load and stalling the processing thread for a significant amount of time. In case of ASGI application, this could stall the event loop and prevent other requests from being processed, resulting in a denial of service (DoS).

### Impact

Applications that use `python-multipart` to parse form data (or use frameworks that do so) are affected. 

### Original Report

This security issue was reported by:
- GitHub security advisory in Starlette on October 30 by @Startr4ck
- Email to `python-multipart` maintainer on October 3 by @mnqazi

## Affected packages

- `python-multipart < 0.0.18`

## Remediation

Upgrade to a patched release:

- `python-multipart 0.0.18`
