Executive brief
Python-Multipart is a software library used by web applications to process file uploads and form data. A vulnerability in this library allows an attacker to crash or slow down a web service by sending specially crafted, malicious upload requests. This can lead to a denial of service, preventing legitimate users from accessing the application and impacting business operations.
Technical details
A denial of service (DoS) vulnerability exists in python-multipart's MultipartParser due to a lack of resource limits during header parsing. Specifically, the parser does not restrict the number of part headers or the size of individual header values when processing multipart/form-data. An unauthenticated remote attacker can exploit this by sending a request containing many repeated headers or an exceptionally large header value, leading to excessive CPU consumption and event-loop delays in frameworks like FastAPI or Starlette. The issue is rooted in the HEADER_FIELD and HEADER_VALUE parser states. This vulnerability is resolved in version 0.0.27 by enforcing default limits on header counts and sizes.
Affected products
- Kludex python-multipart < 0.0.27
- Red Hat Exploit Intelligence 0
- Red Hat Migration Toolkit for Applications 8 8
- Red Hat OpenShift Lightspeed any
- Red Hat Red Hat AI Inference Server 3
- Red Hat Red Hat Ansible Automation Platform 2 2
- Red Hat Red Hat Enterprise Linux AI (RHEL AI) 3 3
- Red Hat Red Hat OpenShift AI (RHOAI) any
- Red Hat Red Hat Satellite 6 6
Timeline
- 2026-04-29: advisory: GitHub Advisory GHSA-pp6c-gr5w-3c5g published by Kludex
- 2026-05-13: disclosed: CVE-2026-42561 published
- 2026-06-29: other: Red Hat updated their VEX data for affected products