VDB
CVE-2026-53538
CVE-2026-53538
PUBLISHED
CVSS 3.7 LOW
Reported by GitHub_M · Published June 22, 2026
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form fields past an upstream body inspecting component. This vulnerability is fixed in 0.0.30.
Risk Scores
CVSS 3.1
3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kludex | python-multipart | < 0.0.30 |
| chainguard | wazuh-manager | 0, 0, 0 |
| chainguard | tritonserver-backend-vllm-cuda-12.9 | 0, 0, 0 |
| wolfi | airflow-3 | 0, 0, 0 |
| Kludex | python-multipart | < 0.0.30, < 0.0.30, < 0.0.30 |
| chainguard | airflow-core-3 | 0, 0, 0 |
| chainguard | wazuh-manager-fips | 0, 0, 0 |
| PyPI | python-multipart | 0 |
| chainguard | airflow-postgres-fips-3 | 0, 0, 0 |
| chainguard | litellm | 0, 0, 0 |
| chainguard | airflow-3 | 0, 0, 0 |
Timeline
- Jun 15, 2026 CVE Published
- Jun 23, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 5, 2026 EPSS Score