#1140628 python-multipart: CVE-2026-53537 CVE-2026-53538 CVE-2026-53539 CVE-2026-53540

Package:
src:python-multipart
Source:
src:python-multipart
Submitter:
Salvatore Bonaccorso
Date:
2026-09-25 07:37:03 UTC
Severity:
normal
Tags:
#1140628#5
Date:
2026-06-23 19:13:27 UTC
From:
To:
Hi,

The following vulnerabilities were published for python-multipart.

CVE-2026-53537[0]:
| Python-Multipart is a streaming multipart parser for Python. Prior
| to 0.0.30, parse_options_header parsed Content-Disposition (and
| Content-Type) headers with email.message.Message, which
| transparently applies RFC 2231/5987 decoding. The extended parameter
| syntax (filename*=charset'lang'value, name*=..., and the
| filename*0/filename*1 continuation form) is decoded and surfaced
| under the bare filename/name key, and overrides the plain parameter
| when both are present. RFC 7578 §4.2 explicitly forbids the
| filename* form in multipart/form-data. Components that follow RFC
| 7578, or that do not implement RFC 2231/5987 decoding for
| multipart/form-data (WAFs, proxies, gateways), may interpret such a
| header differently. An attacker can exploit that difference to
| smuggle a different field name or filename past an upstream
| inspector to the backend. This vulnerability is fixed in 0.0.30.


CVE-2026-53538[1]:
| Python-Multipart is a streaming multipart parser for Python. Prior
| to 0.0.30, QuerystringParser treated ; as a field separator in
| application/x-www-form-urlencoded bodies, in addition to &. The
| WHATWG URL standard, modern browsers, and Python's urllib.parse
| (since the CVE-2021-23336 fix) treat only & as a separator. This
| creates a parser differential: the same bytes are tokenized into
| different fields than a WHATWG compliant intermediary would produce,
| allowing an attacker to smuggle extra form fields past an upstream
| body inspecting component. This vulnerability is fixed in 0.0.30.


CVE-2026-53539[2]:
| Python-Multipart is a streaming multipart parser for Python. Prior
| to 0.0.30, when parsing application/x-www-form-urlencoded bodies,
| QuerystringParser located the field separator with a two step
| lookup: it first scanned the entire remaining buffer for &, and only
| when no & existed anywhere ahead did it fall back to scanning for ;.
| For a body that uses ; as the separator and contains no &, every
| field iteration performed a full failed & scan over the entire
| remaining buffer before locating the nearby ;. With N semicolon
| separated fields in a chunk of size B, this yields O(B^2) byte
| comparisons per chunk. An attacker can submit a small crafted body
| of the form a;a;a;... and cause the parser to spend seconds of CPU
| per request. A handful of concurrent requests can exhaust worker
| processes. This vulnerability is fixed in 0.0.30.


CVE-2026-53540[3]:
| Python-Multipart is a streaming multipart parser for Python. Prior
| to 0.0.31, parse_form() did not validate the Content-Length header
| before using it to bound its chunked read of the request body. A
| negative Content-Length turned the bounded read into a read-until-
| EOF, so the entire body was loaded into memory in a single read
| instead of in fixed-size chunks. This vulnerability is fixed in
| 0.0.31.

More details are in the respective GHSA's tracked in the
debian-security-tracker.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-53537
https://www.cve.org/CVERecord?id=CVE-2026-53537
https://github.com/Kludex/python-multipart/security/advisories/GHSA-vffw-93wf-4j4q
[1] https://security-tracker.debian.org/tracker/CVE-2026-53538
https://www.cve.org/CVERecord?id=CVE-2026-53538
https://github.com/Kludex/python-multipart/security/advisories/GHSA-6jv3-5f52-599m
[2] https://security-tracker.debian.org/tracker/CVE-2026-53539
https://www.cve.org/CVERecord?id=CVE-2026-53539
https://github.com/Kludex/python-multipart/security/advisories/GHSA-5rvq-cxj2-64vf
[3] https://security-tracker.debian.org/tracker/CVE-2026-53540
https://www.cve.org/CVERecord?id=CVE-2026-53540
https://github.com/Kludex/python-multipart/security/advisories/GHSA-v9pg-7xvm-68hf

Regards,
Salvatore

#1140628#10
Date:
2026-09-25 07:34:49 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-multipart, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140628@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sandro Tosi <morph@debian.org> (supplier of updated python-multipart package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 25 Sep 2026 03:16:51 -0400
Source: python-multipart
Architecture: source
Version: 0.0.32-1
Distribution: unstable
Urgency: medium
Maintainer: Sandro Tosi <morph@debian.org>
Changed-By: Sandro Tosi <morph@debian.org>
Closes: 1136702 1140628 1143451
Changes:
 python-multipart (0.0.32-1) unstable; urgency=medium
 .
   * New upstream release
     - fixes CVE-2026-42561; Closes: #1136702
     - fixes CVE-2026-53537, CVE-2026-53538, CVE-2026-53539, CVE-2026-53540;
       Closes: #1140628
   * debian/control
     - drop the transitional Provides on python3-multipart, it is now a real,
       API-incompatible package from src:multipart; Closes: #1143451
     - drop Breaks/Replaces on python3-multipart (<< 0.0.17-2), no longer
       needed after the trixie release
     - bump debhelper compat to 14, drop the now automatic substvars
     - explicitly activate the single-binary dh addon
     - drop Priority and Rules-Requires-Root, the defaults already
     - drop unneeded build-dependencies, mark test-only ones <!nocheck>
     - update Homepage to the new upstream location
     - bump Standards-Version to 4.7.4 (no changes needed)
   * debian/rules
     - let pybuild run the tests against the built module
   * debian/copyright
     - update upstream location and contact
     - remove stanza for files no longer shipped upstream
     - extend packaging copyright years
   * debian/watch
     - convert to version 5, track the new upstream location
   * debian/upstream/metadata
     - update to the new upstream location, add Changelog and Documentation
   * debian/patches/install-only-python_multipart.patch
     - add DEP-3 header, refresh
   * debian/source/options
     - remove, egg-info is no longer generated since the switch to hatchling
Checksums-Sha1:
 3e2d133ea68d77130bba0b7502b4304f78e62647 2130 python-multipart_0.0.32-1.dsc
 13cdbeeb7cbff7e08d642d24cfd3cfdfffdcab7a 109464 python-multipart_0.0.32.orig.tar.xz
 024489d42e62319a8c939d7d23024d1eacefade4 3040 python-multipart_0.0.32-1.debian.tar.xz
 cfd64fa7281c7ed2138293f3d0e928d72509ab0b 8051 python-multipart_0.0.32-1_source.buildinfo
Checksums-Sha256:
 363ae2b5807a3f2d8824b1cb9711ee6c58d65962e50f5145cc1dc5918125f2c3 2130 python-multipart_0.0.32-1.dsc
 d37d0d990a59290f236afda3dd89502998bf2cd314082859a673bed7756a1f1a 109464 python-multipart_0.0.32.orig.tar.xz
 ed95fc1aae9bedbf0f05edbf52b94410e1b31a870a63a5864214374f4782a1fb 3040 python-multipart_0.0.32-1.debian.tar.xz
 b97066e8e402f38f4a7a7a68f5420de927f44ae240f946a8cf49951cbf1bf932 8051 python-multipart_0.0.32-1_source.buildinfo
Files:
 215d8a01f2e1444cea60b8155629dbc2 2130 python optional python-multipart_0.0.32-1.dsc
 9b05a4de70e870a02e89b37d829e6abf 109464 python optional python-multipart_0.0.32.orig.tar.xz
 333d59a319e7cd85c23c8ad418159572 3040 python optional python-multipart_0.0.32-1.debian.tar.xz
 2f8cb6f934fef93411889b1643985c42 8051 python optional python-multipart_0.0.32-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEufrTGSrz5KUwnZ05h588mTgBqU8FAmq2H/UACgkQh588mTgB
qU+QUw/+I7Mb4CI4bp1FRSC18OAuSIyMiUsVm3Dxu4smJVd6eJGV+V9tt1VQPH/6
HKHLtzXSOiyFuIttLH5l+y64YeHVRCzD6jKmkv8SLF9Yb8AYCIjWcQ3T5gQ0NDLO
ZRy2ey2lqYSM2LDEuSlNcuK7r6QuR5kKF7bbRL5kvtYZsjKP+uXsxB2D1pArloyC
GedfO1eYM5Z5eaxR5ZCAgiGk8NFJXqtL/Ov2SWklQw4Ym28b5hd01CPqIXfIj3PK
CfyvOVri4dRgR2QW8BknpAXHLRYF6kVsfNZBSIE2v/5wJjaW/f/aUxpdVFv4A0jH
GdzKDXDUQhN4YbjZhOgLHrBdC9z76axZg4ySKtABWSVjnntO8INgbA0nXYlSSa6c
X/s9LwxP2SeSv+93tOFFrvOGGurfPbfxkWr+yNYmxSKpMTGurqnM5YtZiSax/jqy
BdGO/rYOlhelUw/EuuyH0l3s0SB3dZsCU8W7RqzjG8cSVXdlac9F2eMd8mX7xCGT
3iuP92sRj6VC/g0VTszpkhZmBvI2W6YIxTXLgyzZwFKQdDbdHaFY8KL7BS3Otf/+
wfu2WDJuHOQJnmlG4dI3zujkD//sp+fBPpI2Nj6+e2qis2gf4kcA4lZbxz2DihjJ
P186zKd5ujMg0GQqAB07czXYkvVT06tzEs8LsaY5n/XHPxcvCY8=
=PSZa
-----END PGP SIGNATURE-----