Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-53540

CVE-2026-53540: Python-Multipart DOS Vulnerability

CVE-2026-53540 is a denial of service vulnerability in Python-Multipart caused by improper Content-Length validation. Attackers can exhaust memory by sending negative values. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-53540 Overview

CVE-2026-53540 affects python-multipart, a streaming multipart parser used by Python web frameworks to handle form submissions. Versions prior to 0.0.31 fail to validate the Content-Length header before using it to bound chunked reads of the request body. An attacker can supply a negative Content-Length value, which converts the bounded read into a read-until-EOF operation. The entire request body loads into memory in a single read rather than in fixed-size chunks. This defeats the streaming design and enables memory pressure on applications that rely on parse_form(). The vulnerability is fixed in version 0.0.31.

Critical Impact

A remote unauthenticated attacker can send a request with a negative Content-Length header to force the parser to buffer the full request body in memory, resulting in availability impact.

Affected Products

  • python-multipart versions prior to 0.0.31
  • Python web applications invoking parse_form() from the affected library
  • Downstream frameworks bundling vulnerable python-multipart releases

Discovery Timeline

  • 2026-06-22 - CVE-2026-53540 published to the National Vulnerability Database
  • 2026-06-23 - Last updated in NVD database

Technical Details for CVE-2026-53540

Vulnerability Analysis

The flaw resides in the parse_form() function of python-multipart. The parser reads the Content-Length header from the incoming HTTP request and uses it as the upper bound for a chunked read of the request body. The implementation does not check whether the value is a positive integer.

When the header carries a negative integer, the bounded read degrades into an unbounded read-until-EOF. Instead of consuming the body in fixed-size chunks, the parser performs a single read that loads the complete body into memory. The classification under [CWE-1284] reflects improper validation of a value with implied semantic meaning.

The attack requires no authentication and no user interaction. However, exploitation depends on the attacker being able to deliver a sufficiently large body to cause meaningful memory pressure, which raises attack complexity.

Root Cause

The root cause is missing input validation on the Content-Length header. The parser trusts the header value as a non-negative byte count. A negative value bypasses the chunking logic because the comparison used to gate further reads never terminates the loop as intended, collapsing the streaming behavior into a single allocation.

Attack Vector

The attack vector is network-based. An attacker sends an HTTP request containing a multipart body and a Content-Length header set to a negative value, such as -1. The vulnerable application invokes parse_form(), which then reads the entire body in one operation. Repeated requests can exhaust process or container memory, degrading service availability.

No exploit code is publicly available for CVE-2026-53540. Refer to the GitHub Security Advisory GHSA-v9pg-7xvm-68hf for upstream technical details.

Detection Methods for CVE-2026-53540

Indicators of Compromise

  • HTTP requests carrying a negative Content-Length header value reaching Python application endpoints
  • Sudden Python worker memory growth correlated with multipart form submissions
  • Application crashes or out-of-memory kills on services that import python-multipart versions earlier than 0.0.31

Detection Strategies

  • Inspect reverse proxy and web application firewall logs for requests where Content-Length is non-numeric or negative, and reject them at the edge.
  • Inventory Python dependencies across services and flag any environment pinning python-multipart below 0.0.31.
  • Add runtime assertions or middleware that validate Content-Length is a non-negative integer before request bodies reach parse_form().

Monitoring Recommendations

  • Monitor resident memory usage of Python web workers and alert on rapid growth tied to multipart endpoints.
  • Track HTTP 5xx response rates and worker restart counts on endpoints handling file uploads.
  • Aggregate ingress logs in a centralized data lake to baseline normal Content-Length distributions and surface anomalies.

How to Mitigate CVE-2026-53540

Immediate Actions Required

  • Upgrade python-multipart to version 0.0.31 or later across all environments.
  • Audit transitive dependencies, including Starlette and FastAPI deployments, to confirm the patched version is resolved.
  • Configure the upstream proxy or load balancer to drop requests with malformed Content-Length headers.

Patch Information

The maintainers fixed the issue in python-multipart0.0.31 by validating the Content-Length header prior to using it as a read bound. See the GitHub Security Advisory GHSA-v9pg-7xvm-68hf for the full patch reference.

Workarounds

  • Place a reverse proxy in front of the application to enforce Content-Length validation and request body size limits.
  • Add middleware that rejects requests where Content-Length is missing, non-numeric, or negative before invoking the multipart parser.
  • Apply per-process memory limits using container resource constraints or cgroups to contain the impact of a single malicious request.
bash
# Upgrade python-multipart to the fixed version
pip install --upgrade 'python-multipart>=0.0.31'

# Verify the installed version
python -c "import multipart; print(multipart.__version__)"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.