CVE-2026-28356: Defnull Multipart
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential backtracking (ReDoS) when parsing maliciously crafted HTTP or multipart segment headers. This can be abused for denial of service (DoS) attacks against web applications using this library to parse request headers or multipart/form-data streams. The issue is fixed in 1.2.2, 1.3.1 and 1.4.0-dev.
Affected products
- Defnull Multipart: from 1.3.0, before 1.3.1 (fixed in 1.3.1); before 1.2.2 (fixed in 1.2.2)
- Red Hat Lightspeed Core
- Red Hat Openshift Lightspeed
- Red Hat Red Hat Ai Inference Server
- Red Hat Red Hat Ai Inference Server 3.2: before 1774351144 (fixed in 1774351144); before 1774547384 (fixed in 1774547384); before 1775252598 (fixed in 1775252598)
- Red Hat Red Hat Ansible Automation Platform 2
- Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
- Red Hat Red Hat Openshift Ai 2.25: before 1776247907 (fixed in 1776247907); before 1776338381 (fixed in 1776338381); before 1782397826 (fixed in 1782397826); before 1783998774 (fixed in 1783998774); before 1783998857 (fixed in 1783998857)
- Red Hat Red Hat Openshift Ai 3.3: before 1782996080 (fixed in 1782996080)
- Red Hat Red Hat Openshift Ai Rhoai
- Red Hat Red Hat Satellite 6
Published 2026-03-12. Last modified 2026-08-24.