---
id: CVE-2026-42561
aliases:
  - GHSA-pp6c-gr5w-3c5g
  - PYSEC-2026-3039
title: python-multipart has Denial of Service via unbounded multipart part headers
summary: python-multipart has Denial of Service via unbounded multipart part headers
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
vendor: python-multipart
product: python-multipart
ecosystem: pip
affected:
  - python-multipart < 0.0.27
patched:
  - python-multipart 0.0.27
published: '2026-05-06'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:47.215892833Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-pp6c-gr5w-3c5g'
references:
  - url: >-
      https://github.com/Kludex/python-multipart/security/advisories/GHSA-pp6c-gr5w-3c5g
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-42561'
  - url: 'https://github.com/Kludex/python-multipart'
tags:
  - osv
  - pip
epss: 0.00849
epssPercentile: 0.56296
ingestedAt: '2026-07-13T18:58:01.583Z'
---

## Overview

### Summary

`python-multipart` has a denial of service vulnerability in multipart part header parsing. When parsing `multipart/form-data`, `MultipartParser` previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request rejection or completion.

### Impact

Applications that parse attacker-controlled `multipart/form-data` with affected versions of `python-multipart` can experience CPU exhaustion. ASGI applications using Starlette, FastAPI, or other frameworks that invoke `python-multipart` may have worker or event-loop delays while processing malicious upload requests.

### Details

The affected parser states are `HEADER_FIELD_START`, `HEADER_FIELD`, `HEADER_VALUE_START`, `HEADER_VALUE`, and `HEADER_VALUE_ALMOST_DONE`. The issue can be triggered by:

- A multipart part with an oversized individual header value.
- A multipart part with many repeated header lines or an unterminated header block.

Both variants are addressed by enforcing default parser limits for maximum header count and maximum header size.

### Mitigation

Upgrade to `python-multipart` `0.0.27` or later.

If upgrading is not immediately possible, reduce exposure by enforcing request body size limits at the server, proxy, or framework layer. This is only a mitigation; affected versions of `python-multipart` still parse multipart part headers without the default header count and header size limits.

## Affected packages

- `python-multipart < 0.0.27`

## Remediation

Upgrade to a patched release:

- `python-multipart 0.0.27`
