Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-40347

Опубликовано: 18 апр. 2026
Источник: debian
EPSS Низкий

Описание

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
python-multipartfixed0.0.26-1package
python-multipartno-dsatrixiepackage
python-multipartno-dsabookwormpackage
python-multipartpostponedbullseyepackage

Примечания

  • https://github.com/Kludex/python-multipart/security/advisories/GHSA-mj87-hwqh-73pj

  • https://github.com/Kludex/python-multipart/pull/259

  • Fixed by: https://github.com/Kludex/python-multipart/commit/d4452a78bbde94995dd3c0d1b4aff3610a5c472f (0.0.26)

EPSS

Процентиль: 28%
0.00351
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.

CVSS3: 5.9
redhat
4 месяца назад

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.

CVSS3: 5.3
nvd
4 месяца назад

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.

CVSS3: 5.3
github
4 месяца назад

python-multipart affected by Denial of Service via large multipart preamble or epilogue data

suse-cvrf
2 месяца назад

Security update for python-python-multipart

EPSS

Процентиль: 28%
0.00351
Низкий