VulnSea

python-multipart vulnerabilities

CVEs whose affected-version data names the python-multipart package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

9 CVEsRSS

CVE-2026-53537Low· 3.7
3mo ago

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters

Sunlitpython-multipart · python-multipartEPSS 0.29%via OSV
CVE-2026-53538Low· 3.7
3mo ago

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

Sunlitpython-multipart · python-multipartEPSS 0.26%via OSV
CVE-2026-53540Low· 3.7
3mo ago

python-multipart: Negative Content-Length in parse_form buffers the entire body in memory

python-multipart: Negative Content-Length in parse_form buffers the entire body in memory

Sunlitpython-multipart · python-multipartEPSS 0.34%via OSV
CVE-2026-53539High· 7.5
3mo ago

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

Twilightpython-multipart · python-multipartEPSS 0.46%via OSV
CVE-2026-42561High· 7.5
4mo ago

python-multipart has Denial of Service via unbounded multipart part headers

python-multipart has Denial of Service via unbounded multipart part headers

Twilightpython-multipart · python-multipartEPSS 0.74%via OSV
CVE-2026-40347Medium· 5.3
5mo ago

python-multipart affected by Denial of Service via large multipart preamble or epilogue data

python-multipart affected by Denial of Service via large multipart preamble or epilogue data

Sunlitpython-multipart · python-multipartEPSS 0.35%via OSV
CVE-2026-24486High· 8.6PoC
7mo ago

Python-Multipart is a streaming multipart parser for Python

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write …

Midnightfastapiexpert · python-multipartEPSS 2.2%via NVD
CVE-2024-53981High· 7.5
1y ago

Denial of service (DoS) via deformation `multipart/form-data` boundary

Denial of service (DoS) via deformation `multipart/form-data` boundary

Twilightpython-multipart · python-multipartEPSS 0.64%via OSV
CVE-2024-24762High· 7.5
2y ago

python-multipart vulnerable to Content-Type Header ReDoS

python-multipart vulnerable to Content-Type Header ReDoS

Twilightpython-multipart · python-multipartEPSS 1.5%via OSV
python-multipart vulnerabilities (CVEs) · VulnSea