Skip to main content
EPSS 0.7%top 47%

Kimi cli: python-multipart has Denial of Service via unbounded multipart part headers (CVE-2026-42561)

0
High
Published: 08/13/2026 (08/13/2026, 17:01:40 UTC)
Source: GCVE Database
Product: kimi-cli

Description

### Summary `python-multipart` has a denial of service vulnerability in multipart part header parsing. When parsing `multipart/form-data`, `MultipartParser` previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request rejection or completion. ### Impact Applications that parse attacker-controlled `multipart/form-data` with affected versions of `python-multipart` can experience CPU exhaustion. ASGI applications using Starlette, FastAPI, or other frameworks that invoke `python-multipart` may have worker or event-loop delays while processing malicious upload requests. ### Details The affected parser states are `HEADER_FIELD_START`, `HEADER_FIELD`, `HEADER_VALUE_START`, `HEADER_VALUE`, and `HEADER_VALUE_ALMOST_DONE`. The issue can be triggered by: - A multipart part with an oversized individual header value. - A multipart part with many repeated header lines or an unterminated header block. Both variants are addressed by enforcing default parser limits for maximum header count and maximum header size. ### Mitigation Upgrade to `python-multipart` `0.0.27` or later. If upgrading is not immediately possible, reduce exposure by enforcing request body size limits at the server, proxy, or framework layer. This is only a mitigation; affected versions of `python-multipart` still parse multipart part headers without the default header count and header size limits.

CVSS v3.1

Score 7.5high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected software

python-multipart
pkg:pypi/python-multipart
Affected versions
*
Homebrewmore threats →ghsa
kimi-cli
pkg:brew/kimi-cli
Affected versions
>=0.40 <1.40.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/12/2026, 06:46:53 UTC

Technical Analysis

A denial of service vulnerability (CVE-2026-42561) exists in python-multipart, a component used by Red Hat Satellite Lightspeed. The flaw allows a remote attacker to trigger excessive CPU consumption by sending multipart/form-data requests with an excessive number of part headers or a single very large header value. This leads to resource exhaustion and service disruption. The vulnerability is tracked under CWE-606 (Unchecked Input for Loop Condition) and CWE-770 (Allocation of Resources Without Limits or Throttling). Red Hat has published advisories describing the issue and made a new container image available as a Technology Preview, but no official fix has been released yet.

Potential Impact

The vulnerability can cause denial of service by exhausting CPU resources on affected systems running Red Hat Satellite Lightspeed. This results in service disruption and unavailability. There is no impact on confidentiality or integrity. The attack requires no privileges or user interaction and can be triggered remotely over the network.

Mitigation Recommendations

Red Hat has not released an official fix for this vulnerability yet. The advisory states a new container image is available as a Technology Preview but does not provide a patch. Users should monitor Red Hat Satellite documentation and advisories for updates. No specific mitigations are provided by Red Hat at this time. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:51219
Cve Count
1
State
PUBLISHED

Threat ID: 6a757398bf8831d539d911a7

Added to database: 08/07/2026, 05:56:40 UTC

Last enriched: 09/12/2026, 06:46:53 UTC

Last updated: 09/22/2026, 13:47:45 UTC

Views: 47

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses