Security: Kludex/python-multipart
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Content-Disposition parameter smuggling via RFC 2231/5987 extended parametersGHSA-vffw-93wf-4j4q published
Jun 4, 2026 by KludexLow -
Semicolon treated as querystring field separator enables parameter smugglingGHSA-6jv3-5f52-599m published
Jun 4, 2026 by KludexLow -
Quadratic-time querystring parsing with semicolon separators causes CPU denial of serviceGHSA-5rvq-cxj2-64vf published
Jun 4, 2026 by KludexHigh -
Negative Content-Length in parse_form buffers the entire body in memoryGHSA-v9pg-7xvm-68hf published
Jun 4, 2026 by KludexLow -
Denial of Service via large multipart preamble or epilogue dataGHSA-mj87-hwqh-73pj published
Apr 14, 2026 by KludexModerate -
Denial of Service via unbounded multipart part headersGHSA-pp6c-gr5w-3c5g published
Apr 29, 2026 by KludexHigh -
Arbitrary file write via a non-default configurationGHSA-wp53-j4wj-2cfg published
Jan 25, 2026 by KludexHigh -
Denial of service (DoS) via deformation `multipart/form-data` boundaryGHSA-59g5-xgcq-4qw3 published
Nov 30, 2024 by KludexHigh -
Content-Type Header ReDoSGHSA-2jv5-9r88-3w3p published
Feb 12, 2024 by KludexHigh