python-multipart has 8 CVEs on record between 2024 and 2026. Disclosures have slowed: 0 in the last 90 days after 6 in the 90 before. The busiest recent month was June 2026 with 4. The median CVSS is 6.4 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.4
- Publish → KEV
- —
- Last 90 days
- 0 prev 6
Weakness classes
Products
- python-multipart 8
Worst active — by depth score
CVE-2024-24762High· 7.5python-multipart vulnerable to Content-Type Header ReDoS42CVE-2026-53539High· 7.5python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service41CVE-2026-42561High· 7.5python-multipart has Denial of Service via unbounded multipart part headers41CVE-2024-53981High· 7.5Denial of service (DoS) via deformation `multipart/form-data` boundary41CVE-2026-40347Medium· 5.3python-multipart affected by Denial of Service via large multipart preamble or epilogue data29
python-multipart vulnerabilities
CVEs affecting python-multipart, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-53537Low· 3.7python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
CVE-2026-53538Low· 3.7python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
CVE-2026-53540Low· 3.7python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
CVE-2026-53539High· 7.5python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
CVE-2026-42561High· 7.5python-multipart has Denial of Service via unbounded multipart part headers
python-multipart has Denial of Service via unbounded multipart part headers
CVE-2026-40347Medium· 5.3python-multipart affected by Denial of Service via large multipart preamble or epilogue data
python-multipart affected by Denial of Service via large multipart preamble or epilogue data
CVE-2024-53981High· 7.5Denial of service (DoS) via deformation `multipart/form-data` boundary
Denial of service (DoS) via deformation `multipart/form-data` boundary
CVE-2024-24762High· 7.5python-multipart vulnerable to Content-Type Header ReDoS
python-multipart vulnerable to Content-Type Header ReDoS