CVE-2026-40347

Name
CVE-2026-40347
Description
Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/Kludex/python-multipart/releases/tag/0.0.26
security-advisories@github.com https://github.com/Kludex/python-multipart/security/advisories/GHSA-mj87-hwqh-73pj

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:fastapiexpert:python-multipart:*:*:*:*:*:python:*:* py3-python-multipart >= None < 0.0.26

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
py3-python-multipart edge-community 0.0.24-r0 Oleg Titov <oleg.titov@gmail.com> possibly vulnerable
py3-python-multipart edge-community 0.0.22-r1 Oleg Titov <oleg.titov@gmail.com> possibly vulnerable
py3-python-multipart edge-community 0.0.22-r0 Oleg Titov <oleg.titov@gmail.com> possibly vulnerable
py3-python-multipart edge-community 0.0.21-r0 Oleg Titov <oleg.titov@gmail.com> possibly vulnerable
py3-python-multipart edge-community 0.0.20-r0 Oleg Titov <oleg.titov@gmail.com> possibly vulnerable
py3-python-multipart edge-community 0.0.19-r0 Oleg Titov <oleg.titov@gmail.com> possibly vulnerable
py3-python-multipart 3.23-community 0.0.20-r0 Oleg Titov <oleg.titov@gmail.com> possibly vulnerable