---
id: CVE-2026-55256
title: >-
  In parsePartHeaders of multiple files, there is a possible persistent denial
  of service due to improper input validation
summary: >-
  In parsePartHeaders of multiple files, there is a possible persistent denial
  of service due to improper input validation. This could lead to remote denial
  of service with no additional execution privileges needed. User interaction is
  not…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
vendor: google
product: android
affected:
  - android = 14.0
  - android = 15.0
  - android = 16.0
  - android = 17.0
published: '2026-09-08'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T15:42:54.473'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55256'
references:
  - url: 'https://source.android.com/docs/security/bulletin/2026/2026-09-01'
    label: security@android.com
tags:
  - nvd
  - cve.org
epss: 0.00259
epssPercentile: 0.179
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T15:40:12.250851Z'
ingestedAt: '2026-09-08T19:08:49.641Z'
---

## Overview

In parsePartHeaders of multiple files, there is a possible persistent denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

## Affected

- `android = 14.0`
- `android = 15.0`
- `android = 16.0`
- `android = 17.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
