18 Total advisories
18 Vulnerabilities
0 Malware
Dependency scanning
Check whether python-multipart is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
LOW 3.7
CVE-2026-53538
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
MEDIUM 5.3
CVE-2026-40347
python-multipart affected by Denial of Service via large multipart preamble or epilogue data
HIGH 8.6
CVE-2026-24486
Python-Multipart has Arbitrary File Write via Non-Default Configuration
LOW 3.7
CVE-2026-53540
python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
LOW 3.7
CVE-2026-53537
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
HIGH 7.5
CVE-2026-53539
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
HIGH 7.5
CVE-2026-42561
python-multipart has Denial of Service via unbounded multipart part headers
HIGH 7.5
CVE-2024-53981
Denial of service (DoS) via deformation `multipart/form-data` boundary
HIGH 7.5
CVE-2024-24762
python-multipart vulnerable to Content-Type Header ReDoS
LOW 3.7
CVE-2026-53537
python-multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters
LOW 3.7
CVE-2026-53540
python-multipart: Negative Content-Length in parse_form buffers the entire body in memory
MEDIUM 5.3
CVE-2026-40347
python-multipart affected by Denial of Service via large multipart preamble or epilogue data
HIGH 7.5
CVE-2026-42561
python-multipart has Denial of Service via unbounded multipart part headers
HIGH 7.5
CVE-2026-53539
python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
LOW 3.7
CVE-2026-53538
python-multipart: Semicolon treated as querystring field separator enables parameter smuggling
HIGH 7.5
CVE-2024-24762
python-multipart vulnerable to Content-Type Header ReDoS
HIGH 8.6
CVE-2026-24486
Python-Multipart has Arbitrary File Write via Non-Default Configuration
HIGH 7.5
CVE-2024-53981
Denial of service (DoS) via deformation `multipart/form-data` boundary
Browse more PyPI advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes