Junglewise Threat Intelligence

CVE-2026-42561: Kludex python-multipart denial of service in multipart header parsing

CVE-2026-42561 · Severity: high · CVSS 7.5 · Published 2026-05-13

Technologies: Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift Lightspeed, python-multipart (PyPI), Red Hat AI Inference Server. Vendors: Kludex, Red Hat, PyPI.

Executive brief

Python-Multipart is a software library used by web applications to process file uploads and form data. A vulnerability in this library allows an attacker to crash or slow down a web service by sending specially crafted, malicious upload requests. This can lead to a denial of service, preventing legitimate users from accessing the application and impacting business operations.

Technical details

A denial of service (DoS) vulnerability exists in python-multipart's MultipartParser due to a lack of resource limits during header parsing. Specifically, the parser does not restrict the number of part headers or the size of individual header values when processing multipart/form-data. An unauthenticated remote attacker can exploit this by sending a request containing many repeated headers or an exceptionally large header value, leading to excessive CPU consumption and event-loop delays in frameworks like FastAPI or Starlette. The issue is rooted in the HEADER_FIELD and HEADER_VALUE parser states. This vulnerability is resolved in version 0.0.27 by enforcing default limits on header counts and sizes.

Affected products

  • Kludex python-multipart < 0.0.27
  • Red Hat Exploit Intelligence 0
  • Red Hat Migration Toolkit for Applications 8 8
  • Red Hat OpenShift Lightspeed any
  • Red Hat Red Hat AI Inference Server 3
  • Red Hat Red Hat Ansible Automation Platform 2 2
  • Red Hat Red Hat Enterprise Linux AI (RHEL AI) 3 3
  • Red Hat Red Hat OpenShift AI (RHOAI) any
  • Red Hat Red Hat Satellite 6 6

Timeline

  • 2026-04-29: advisory: GitHub Advisory GHSA-pp6c-gr5w-3c5g published by Kludex
  • 2026-05-13: disclosed: CVE-2026-42561 published
  • 2026-06-29: other: Red Hat updated their VEX data for affected products

References

Related threats