python-multipart vulnerabilities
CVEs whose affected-version data names the python-multipart package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
9 CVEsRSS
CVE-2026-53537Low· 3.7python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
CVE-2026-53538Low· 3.7python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
CVE-2026-53540Low· 3.7python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
CVE-2026-53539High· 7.5python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
CVE-2026-42561High· 7.5python-multipart has Denial of Service via unbounded multipart part headers
python-multipart has Denial of Service via unbounded multipart part headers
CVE-2026-40347Medium· 5.3python-multipart affected by Denial of Service via large multipart preamble or epilogue data
python-multipart affected by Denial of Service via large multipart preamble or epilogue data
CVE-2026-24486High· 8.6PoCPython-Multipart is a streaming multipart parser for Python
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write …
CVE-2024-53981High· 7.5Denial of service (DoS) via deformation `multipart/form-data` boundary
Denial of service (DoS) via deformation `multipart/form-data` boundary
CVE-2024-24762High· 7.5python-multipart vulnerable to Content-Type Header ReDoS
python-multipart vulnerable to Content-Type Header ReDoS