Debian Package Tracker
Register | Log in
Subscribe

python-multipart

streaming multipart parser for Python

Choose email to subscribe with

general
  • source: python-multipart (main)
  • version: 0.0.32-1
  • maintainer: Sandro Tosi (DMD)
  • arch: all
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 0.0.5-2
  • oldstable: 0.0.5-3
  • stable: 0.0.20-1.1~deb13u1
  • testing: 0.0.32-1
  • unstable: 0.0.32-1
versioned links
  • 0.0.5-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.0.5-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.0.20-1.1~deb13u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 0.0.32-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • python3-python-multipart
action needed
6 low-priority security issues in trixie low

There are 6 open security issues in trixie.

6 issues left for the package maintainer to handle:
  • CVE-2026-40347: (needs triaging) Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or epilogue sections. Upgrade to version 0.0.26 or later, which skips ahead to the next boundary candidate when processing leading CR/LF data and immediately discards epilogue data after the closing boundary.
  • CVE-2026-42561: (needs triaging) Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request rejection or completion. This vulnerability is fixed in 0.0.27.
  • CVE-2026-53537: (needs triaging) Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 §4.2 explicitly forbids the filename* form in multipart/form-data. Components that follow RFC 7578, or that do not implement RFC 2231/5987 decoding for multipart/form-data (WAFs, proxies, gateways), may interpret such a header differently. An attacker can exploit that difference to smuggle a different field name or filename past an upstream inspector to the backend. This vulnerability is fixed in 0.0.30.
  • CVE-2026-53538: (needs triaging) Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form fields past an upstream body inspecting component. This vulnerability is fixed in 0.0.30.
  • CVE-2026-53539: (needs triaging) Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to scanning for ;. For a body that uses ; as the separator and contains no &, every field iteration performed a full failed & scan over the entire remaining buffer before locating the nearby ;. With N semicolon separated fields in a chunk of size B, this yields O(B^2) byte comparisons per chunk. An attacker can submit a small crafted body of the form a;a;a;... and cause the parser to spend seconds of CPU per request. A handful of concurrent requests can exhaust worker processes. This vulnerability is fixed in 0.0.30.
  • CVE-2026-53540: (needs triaging) Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-04-18 Last update: 2026-10-04 18:31
news
[rss feed]
  • [2026-10-05] python-multipart 0.0.32-1 MIGRATED to testing (Debian testing watch)
  • [2026-09-25] Accepted python-multipart 0.0.32-1 (source) into unstable (Sandro Tosi)
  • [2026-06-03] python-multipart 0.0.26-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-15] Accepted python-multipart 0.0.26-1 (source) into unstable (Sandro Tosi)
  • [2026-03-11] python-multipart 0.0.22-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-08] Accepted python-multipart 0.0.20-1.1~deb13u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Salvatore Bonaccorso)
  • [2026-03-08] Accepted python-multipart 0.0.22-1 (source) into unstable (Sandro Tosi)
  • [2026-02-10] python-multipart 0.0.20-1.1 MIGRATED to testing (Debian testing watch)
  • [2026-02-06] Accepted python-multipart 0.0.20-1.1 (source) into unstable (Salvatore Bonaccorso)
  • [2025-03-16] python-multipart 0.0.20-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-14] Accepted python-multipart 0.0.20-1 (source) into unstable (Sandro Tosi)
  • [2024-12-21] python-multipart 0.0.17-5 MIGRATED to testing (Debian testing watch)
  • [2024-12-19] Accepted python-multipart 0.0.17-5 (source) into unstable (Sandro Tosi)
  • [2024-11-29] python-multipart 0.0.17-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-27] Accepted python-multipart 0.0.17-4 (source) into experimental (Sandro Tosi)
  • [2024-11-27] Accepted python-multipart 0.0.17-3 (source) into experimental (Sandro Tosi)
  • [2024-11-26] Accepted python-multipart 0.0.17-2 (source all) into experimental (Debian FTP Masters) (signed by: Sandro Tosi)
  • [2024-11-24] Accepted python-multipart 0.0.17-1 (source) into unstable (Sandro Tosi)
  • [2024-03-06] python-multipart 0.0.9-1 MIGRATED to testing (Debian testing watch)
  • [2024-03-02] Accepted python-multipart 0.0.9-1 (source) into unstable (Sandro Tosi)
  • [2024-01-19] python-multipart 0.0.6-1 MIGRATED to testing (Debian testing watch)
  • [2024-01-13] Accepted python-multipart 0.0.6-1 (source) into unstable (Sandro Tosi)
  • [2022-10-28] python-multipart 0.0.5-3 MIGRATED to testing (Debian testing watch)
  • [2022-10-23] Accepted python-multipart 0.0.5-3 (source) into unstable (Sandro Tosi)
  • [2021-01-16] python-multipart 0.0.5-2 MIGRATED to testing (Debian testing watch)
  • [2021-01-11] Accepted python-multipart 0.0.5-2 (source) into unstable (Sandro Tosi)
  • [2021-01-10] Accepted python-multipart 0.0.5-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Sandro Tosi)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 0.0.32-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing