CVE-2026-42561: Kludex Python-Multipart

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, MultipartParser previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request rejection or completion. This vulnerability is fixed in 0.0.27.

Affected products

  • Kludex Python-Multipart: before 0.0.27 (fixed in 0.0.27)
  • Red Hat Exploit Intelligence
  • Red Hat Openshift Lightspeed
  • Red Hat Red Hat Ai Inference Server
  • Red Hat Red Hat Ansible Automation Platform 2
  • Red Hat Red Hat Ansible Automation Platform 2.6: before 1783832856 (fixed in 1783832856); before 1783920640 (fixed in 1783920640)
  • Red Hat Red Hat Ansible Automation Platform 2.7: before 1783923914 (fixed in 1783923914); before 1783918403 (fixed in 1783918403)
  • Red Hat Red Hat Enterprise Linux Ai Rhel Ai 3
  • Red Hat Red Hat Migration Toolkit For Applications 8.2: before 1784109883 (fixed in 1784109883)
  • Red Hat Red Hat Openshift Ai 3.3: before 1782887848 (fixed in 1782887848)
  • Red Hat Red Hat Openshift Ai Rhoai
  • Red Hat Red Hat Satellite 6
  • Red Hat Red Hat Satellite 6.17: before 1784834402 (fixed in 1784834402)
  • Red Hat Red Hat Satellite 6.19: before 1785929994 (fixed in 1785929994); before 1785806554 (fixed in 1785806554)

Published 2026-05-13. Last modified 2026-08-07.