CVE-2026-42561: Kludex Python-Multipart
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request rejection or completion. This vulnerability is fixed in 0.0.27.
Affected products
- Kludex Python-Multipart: before 0.0.27 (fixed in 0.0.27)
- Red Hat Exploit Intelligence
- Red Hat Openshift Lightspeed
- Red Hat Red Hat Ai Inference Server
- Red Hat Red Hat Ansible Automation Platform 2
- Red Hat Red Hat Ansible Automation Platform 2.6: before 1783832856 (fixed in 1783832856); before 1783920640 (fixed in 1783920640)
- Red Hat Red Hat Ansible Automation Platform 2.7: before 1783923914 (fixed in 1783923914); before 1783918403 (fixed in 1783918403)
- Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
- Red Hat Red Hat Migration Toolkit For Applications 8.2: before 1784109883 (fixed in 1784109883)
- Red Hat Red Hat Openshift Ai 3.3: before 1782887848 (fixed in 1782887848)
- Red Hat Red Hat Openshift Ai Rhoai
- Red Hat Red Hat Satellite 6
- Red Hat Red Hat Satellite 6.17: before 1784834402 (fixed in 1784834402)
- Red Hat Red Hat Satellite 6.19: before 1785929994 (fixed in 1785929994); before 1785806554 (fixed in 1785806554)
Published 2026-05-13. Last modified 2026-08-07.