LOW🇬🇧 English

CVE-2026-53538

CVSS 3.7v3.1pub. 2026-06-22upd. 2026-06-26

Python-Multipart to parser streamingowy dla multipart w Pythonie. Przed wersją 0.0.30 QuerystringParser traktował znak ; jako separator pól w телach application/x-www-form-urlencoded, oprócz &. Standard WHATWG URL, nowoczesne przeglądarki i urllib.parse Pythona (od poprawki CVE-2021-23336) traktują tylko & jako separator. Tworzy to różnicę parserów: te same bajty są tokenizowane na różne pola niż by wytworzyła zgodna ze standardem WHATWG pośrednia komponenta, umożliwiając atakującemu smugglowanie dodatkowych pól formularza obok upstream'owego komponentu inspekcji ciała. Podatność ta została naprawiona w wersji 0.0.30.

Pokaż oryginał (EN)

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form fields past an upstream body inspecting component. This vulnerability is fixed in 0.0.30.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
  • Fastapiexpert Python Multipart

    APP
    Fastapiexpert
    < 0.0.30
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-53539HIGH7.5ten sam produkt

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-f...

CVE-2026-24486HIGH8.6ten sam produkt

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnera...

CVE-2024-24762HIGH7.5ten sam produkt

`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a...

CVE-2026-40347MEDIUM5.3ten sam produkt

Python-Multipart to parser streamingowy multipart dla Pythona. Wersje wcześniejsze niż 0.0.26 mają podatność D...

CVE-2026-53537LOW3.7ten sam produkt

Python-Multipart to parser strumieni multipart dla Pythona. Przed wersją 0.0.30 funkcja parse_options_header a...