CVE-2026-53537
Reported by GitHub_M · Published June 22, 2026
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 §4.2 explicitly forbids the filename* form in multipart/form-data. Components that follow RFC 7578, or that do not implement RFC 2231/5987 decoding for multipart/form-data (WAFs, proxies, gateways), may interpret such a header differently. An attacker can exploit that difference to smuggle a different field name or filename past an upstream inspector to the backend. This vulnerability is fixed in 0.0.30.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kludex | python-multipart | < 0.0.30 |
| chainguard | tritonserver-backend-vllm-cuda-12.9 | 0, 0, 0 |
| PyPI | python-multipart | 0 |
| chainguard | litellm | 0, 0, 0 |
| chainguard | airflow-core-3 | 0, 0, 0 |
| Kludex | python-multipart | < 0.0.30, < 0.0.30, < 0.0.30 |
| chainguard | airflow-postgres-fips-3 | 0, 0, 0 |
| wolfi | airflow-3 | 0, 0, 0 |
| chainguard | wazuh-manager-fips | 0, 0, 0 |
| chainguard | airflow-3 | 0, 0, 0 |
| chainguard | wazuh-manager | 0, 0, 0 |
Timeline
- Jun 15, 2026 CVE Published
- Jun 23, 2026 Security Advisory
- Jun 26, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
References
- https://github.com/Kludex/python-multipart/security/advisories/GHSA-vffw-93wf-4j4q x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-53537 advisory
- https://github.com/advisories/GHSA-vffw-93wf-4j4q advisory
- https://github.com/Kludex/python-multipart url
- https://github.com/pypa/advisory-database/blob/main/vulns/python-multipart/PYSEC-2026-3041.yaml advisory
- https://pypi.org/project/python-multipart url