Логотип exploitDog
bind:CVE-2026-28356
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-28356

Количество 5

Количество 5

ubuntu логотип

CVE-2026-28356

15 дней назад

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential backtracking (ReDoS) when parsing maliciously crafted HTTP or multipart segment headers. This can be abused for denial of service (DoS) attacks against web applications using this library to parse request headers or multipart/form-data streams. The issue is fixed in 1.2.2, 1.3.1 and 1.4.0-dev.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-28356

15 дней назад

A flaw was found in multipart. The parse_options_header function in multipart.py uses a regular expression with an ambiguous alternation, causing an exponential backtracking (ReDoS) when parsing a specially crafted HTTP or multipart segment headers. A web application parsing request headers or multipart/form-data streams can block request handling threads for multiple seconds per request, eventually resulting in a denial of service.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-28356

15 дней назад

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential backtracking (ReDoS) when parsing maliciously crafted HTTP or multipart segment headers. This can be abused for denial of service (DoS) attacks against web applications using this library to parse request headers or multipart/form-data streams. The issue is fixed in 1.2.2, 1.3.1 and 1.4.0-dev.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-28356

15 дней назад

multipart is a fast multipart/form-data parser for python. Prior to 1. ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p2m9-wcp5-6qw3

15 дней назад

multipart vulnerable to ReDoS in `parse_options_header()`

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-28356

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential backtracking (ReDoS) when parsing maliciously crafted HTTP or multipart segment headers. This can be abused for denial of service (DoS) attacks against web applications using this library to parse request headers or multipart/form-data streams. The issue is fixed in 1.2.2, 1.3.1 and 1.4.0-dev.

CVSS3: 7.5
1%
Низкий
15 дней назад
redhat логотип
CVE-2026-28356

A flaw was found in multipart. The parse_options_header function in multipart.py uses a regular expression with an ambiguous alternation, causing an exponential backtracking (ReDoS) when parsing a specially crafted HTTP or multipart segment headers. A web application parsing request headers or multipart/form-data streams can block request handling threads for multiple seconds per request, eventually resulting in a denial of service.

CVSS3: 7.5
1%
Низкий
15 дней назад
nvd логотип
CVE-2026-28356

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential backtracking (ReDoS) when parsing maliciously crafted HTTP or multipart segment headers. This can be abused for denial of service (DoS) attacks against web applications using this library to parse request headers or multipart/form-data streams. The issue is fixed in 1.2.2, 1.3.1 and 1.4.0-dev.

CVSS3: 7.5
1%
Низкий
15 дней назад
debian логотип
CVE-2026-28356

multipart is a fast multipart/form-data parser for python. Prior to 1. ...

CVSS3: 7.5
1%
Низкий
15 дней назад
github логотип
GHSA-p2m9-wcp5-6qw3

multipart vulnerable to ReDoS in `parse_options_header()`

CVSS3: 7.5
1%
Низкий
15 дней назад

Уязвимостей на страницу