VDB
CVE-2026-53540
CVE-2026-53540
PUBLISHED
CVSS 3.7 LOW
Reported by GitHub_M · Published June 22, 2026
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.
Risk Scores
CVSS 3.1
3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kludex | python-multipart | < 0.0.31 |
| wolfi | airflow-3 | 0, 0, 0 |
| Kludex | python-multipart | < 0.0.31, < 0.0.31 |
| PyPI | python-multipart | 0 |
| chainguard | airflow-postgres-fips-3 | 0, 0, 0 |
| chainguard | wazuh-manager | 0, 0, 0 |
| chainguard | tritonserver-backend-vllm-cuda-12.9 | 0, 0, 0 |
| chainguard | wazuh-manager-fips | 0, 0, 0 |
| chainguard | airflow-core-3 | 0, 0, 0 |
| chainguard | airflow-3 | 0, 0, 0 |
| chainguard | litellm | 0, 0, 0 |
Timeline
- Jun 15, 2026 CVE Published
- Jun 23, 2026 Coalition ESS Score
- Jun 23, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 4, 2026 EPSS Score