---
id: CVE-2026-53540
aliases:
  - GHSA-v9pg-7xvm-68hf
  - PYSEC-2026-3040
title: >-
  python-multipart: Negative Content-Length in parse_form buffers the entire
  body in memory
summary: >-
  python-multipart: Negative Content-Length in parse_form buffers the entire
  body in memory
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'
vendor: python-multipart
product: python-multipart
ecosystem: pip
affected:
  - python-multipart < 0.0.31
patched:
  - python-multipart 0.0.31
published: '2026-06-15'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:50.590441047Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-v9pg-7xvm-68hf'
references:
  - url: >-
      https://github.com/Kludex/python-multipart/security/advisories/GHSA-v9pg-7xvm-68hf
  - url: 'https://github.com/Kludex/python-multipart'
  - url: 'https://github.com/advisories/GHSA-v9pg-7xvm-68hf'
tags:
  - osv
  - pip
  - ghsa
epss: 0.00342
epssPercentile: 0.27844
cwe:
  - CWE-1284
ingestedAt: '2026-07-07T15:41:58.645Z'
---

## Overview

### Summary

`parse_form()` did not validate the `Content-Length` header before using it to bound its chunked read of the request body. A negative `Content-Length` turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks.

### Details

`parse_form()` reads the input stream in chunks, never reading more than the remaining `Content-Length` at a time. The per-chunk size is computed as `min(content_length - bytes_read, chunk_size)`. The header value was parsed to an integer without checking its sign, so a `Content-Length` of `-1` made this expression negative, and `input_stream.read(-1)` reads until end of stream. The intended bounded, chunked read therefore collapsed into a single unbounded read of the whole stream. The amount read is still bounded by what the client actually sends.

### Impact

This only affects code that calls `parse_form()` directly with a `Content-Length` header taken from attacker-controlled input and without normalizing a negative value first. No known package is affected:

* Starlette and FastAPI drive `MultipartParser` directly from the ASGI `receive()` stream and do not call `parse_form()`.
* Known `parse_form()` consumers either do not forward `Content-Length` to it, recompute it from the already-read body, or run behind a layer (such as Werkzeug) that normalizes a negative `Content-Length` to `0`.

The realistic exposure is limited to bespoke WSGI or `http.server` handlers that forward raw client headers into `parse_form()`. In that case a crafted request buffers the body in memory at once, degrading availability under concurrent requests rather than causing a complete denial of service.

### Mitigation

Upgrade to version `0.0.31` or later, which rejects a negative `Content-Length` with a `ValueError` before reading the stream.

## Affected packages

- `python-multipart < 0.0.31`

## Remediation

Upgrade to a patched release:

- `python-multipart 0.0.31`
