Executive brief
Python-Multipart is a library used by web applications to process data sent through web forms. A flaw in how it handles specific web headers could allow an attacker to force the application to load an entire large file into memory at once instead of processing it in small pieces. This could lead to increased memory usage and potentially slow down or crash the service if multiple such requests are sent simultaneously.
Technical details
A vulnerability exists in the parse_form() function of python-multipart where the Content-Length header is not validated for negative values. When a negative value is provided, the internal logic min(content_length - bytes_read, chunk_size) results in a negative value being passed to the stream's read() method, which triggers a read-until-EOF behavior. This causes the entire request body to be buffered into memory in a single operation rather than being processed in fixed-size chunks. Exploitation requires the application to call parse_form() directly using raw, un-normalized attacker-controlled headers. The issue is resolved in version 0.0.31.
Affected products
- Kludex python-multipart < 0.0.31
Timeline
- 2026-06-04: advisory: GitHub advisory published by maintainer
- 2026-06-22: disclosed: CVE published to NVD
- 2026-06-22: patched: Fix released in version 0.0.31