HIGH8.6CVE-2026-24486Python-Multipart has Arbitrary File Write via Non-Default Configuration from 0, < 0.0.22
HIGH8.6CVE-2026-24486Python-Multipart has Arbitrary File Write via Non-Default Configuration from 0, < 0.0.22
HIGH7.5CVE-2026-53539python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service from 0, < 0.0.30
HIGH7.5python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
from 0, < 0.0.30
HIGH7.5python-multipart has Denial of Service via unbounded multipart part headers
from 0, < 0.0.27
HIGH7.5python-multipart has Denial of Service via unbounded multipart part headers
from 0, < 0.0.27
HIGH7.5Denial of service (DoS) via deformation `multipart/form-data` boundary
from 0, < 0.0.18
HIGH7.5Denial of service (DoS) via deformation `multipart/form-data` boundary
from 0, < 0.0.18
HIGH7.5python-multipart vulnerable to Content-Type Header ReDoS
from 0, < 0.0.7
HIGH7.5python-multipart vulnerable to Content-Type Header ReDoS
from 0, < 0.0.7
MEDIUM5.3python-multipart affected by Denial of Service via large multipart preamble or epilogue data
from 0, < 0.0.26
MEDIUM5.3python-multipart affected by Denial of Service via large multipart preamble or epilogue data
from 0, < 0.0.26
LOW3.7python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
from 0, < 0.0.31
LOW3.7python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
from 0, < 0.0.31
LOW3.7python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
from 0, < 0.0.30
LOW3.7python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
from 0, < 0.0.30
LOW3.7python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
from 0, < 0.0.30