CVE-2026-24486: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kludex python-multipart
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious filename. Users should upgrade to version 0.0.22 to receive a patch or, as a workaround, avoid using `UPLOAD_KEEP_FILENAME=True` in project configurations.
AI Analysis
Technical Summary
Python-Multipart versions before 0.0.22 contain a CWE-22 path traversal vulnerability triggered when the configuration options UPLOAD_DIR and UPLOAD_KEEP_FILENAME=True are enabled. This flaw allows remote attackers to write files to arbitrary locations on the server by submitting specially crafted filenames during file uploads. The vulnerability impacts confidentiality, integrity, and availability by enabling unauthorized file creation or modification, which could lead to system compromise. The vulnerability is confirmed and documented by Red Hat advisories, which recommend upgrading to version 0.0.22 or disabling the UPLOAD_KEEP_FILENAME=True option to mitigate the risk.
Potential Impact
An attacker can write files to arbitrary locations on the server filesystem, potentially overwriting or creating critical files used for code execution or security mechanisms. This can lead to unauthorized code execution, bypass of security controls, exposure of sensitive data, and denial of service by corrupting essential files. The vulnerability affects confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
A fix is available in python-multipart version 0.0.22. Users should upgrade to this version to fully remediate the vulnerability. As a workaround, avoid enabling the UPLOAD_KEEP_FILENAME=True configuration option when using UPLOAD_DIR, since disabling this option prevents the path traversal vulnerability. Follow vendor advisories for updates and patches.
CVE-2026-24486: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Kludex python-multipart
Description
Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious filename. Users should upgrade to version 0.0.22 to receive a patch or, as a workaround, avoid using `UPLOAD_KEEP_FILENAME=True` in project configurations.
CVSS v3.1
Score 8.6high
Affected software
Kludex
python-multipart
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Python-Multipart versions before 0.0.22 contain a CWE-22 path traversal vulnerability triggered when the configuration options UPLOAD_DIR and UPLOAD_KEEP_FILENAME=True are enabled. This flaw allows remote attackers to write files to arbitrary locations on the server by submitting specially crafted filenames during file uploads. The vulnerability impacts confidentiality, integrity, and availability by enabling unauthorized file creation or modification, which could lead to system compromise. The vulnerability is confirmed and documented by Red Hat advisories, which recommend upgrading to version 0.0.22 or disabling the UPLOAD_KEEP_FILENAME=True option to mitigate the risk.
Potential Impact
An attacker can write files to arbitrary locations on the server filesystem, potentially overwriting or creating critical files used for code execution or security mechanisms. This can lead to unauthorized code execution, bypass of security controls, exposure of sensitive data, and denial of service by corrupting essential files. The vulnerability affects confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
A fix is available in python-multipart version 0.0.22. Users should upgrade to this version to fully remediate the vulnerability. As a workaround, avoid enabling the UPLOAD_KEEP_FILENAME=True configuration option when using UPLOAD_DIR, since disabling this option prevents the path traversal vulnerability. Follow vendor advisories for updates and patches.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-01-23T00:38:20.548Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-24486","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3461","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3462","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3960","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:10184","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3782","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:19712","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:3713","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:1504","vendor":"Red Hat"}]
Threat ID: 69780bf04623b1157cc7aac1
Added to database: 01/27/2026, 00:50:56 UTC
Last enriched: 08/07/2026, 12:56:23 UTC
Last updated: 09/10/2026, 22:18:40 UTC
Views: 611
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.