Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53538

Опубликовано: 22 июн. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form fields past an upstream body inspecting component. This vulnerability is fixed in 0.0.30.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:fastapiexpert:python-multipart:*:*:*:*:*:python:*:*
Версия до 0.0.30 (исключая)

EPSS

Процентиль: 7%
0.00176
Низкий

3.7 Low

CVSS3

Дефекты

CWE-436

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form fields past an upstream body inspecting component. This vulnerability is fixed in 0.0.30.

CVSS3: 4.8
redhat
около 1 месяца назад

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form fields past an upstream body inspecting component. This vulnerability is fixed in 0.0.30.

CVSS3: 3.7
debian
около 1 месяца назад

Python-Multipart is a streaming multipart parser for Python. Prior to ...

CVSS3: 3.7
github
около 2 месяцев назад

python-multipart: Semicolon treated as querystring field separator enables parameter smuggling

suse-cvrf
около 1 месяца назад

Security update for python-python-multipart

EPSS

Процентиль: 7%
0.00176
Низкий

3.7 Low

CVSS3

Дефекты

CWE-436