Allocation of Resources Without Limits or Throttling in python-multipart - CVE-2026-42561
Published: April 30, 2026
python-multipart
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to allocation of resources without limits or throttling in the HEADER_FIELD_START, HEADER_FIELD, HEADER_VALUE_START, HEADER_VALUE and HEADER_VALUE_ALMOST_DONE headers. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.