Kimi cli: python-multipart has Denial of Service via unbounded multipart part headers (CVE-2026-42561)
### Summary `python-multipart` has a denial of service vulnerability in multipart part header parsing. When parsing `multipart/form-data`, `MultipartParser` previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request rejection or completion. ### Impact Applications that parse attacker-controlled `multipart/form-data` with affected versions of `python-multipart` can experience CPU exhaustion. ASGI applications using Starlette, FastAPI, or other frameworks that invoke `python-multipart` may have worker or event-loop delays while processing malicious upload requests. ### Details The affected parser states are `HEADER_FIELD_START`, `HEADER_FIELD`, `HEADER_VALUE_START`, `HEADER_VALUE`, and `HEADER_VALUE_ALMOST_DONE`. The issue can be triggered by: - A multipart part with an oversized individual header value. - A multipart part with many repeated header lines or an unterminated header block. Both variants are addressed by enforcing default parser limits for maximum header count and maximum header size. ### Mitigation Upgrade to `python-multipart` `0.0.27` or later. If upgrading is not immediately possible, reduce exposure by enforcing request body size limits at the server, proxy, or framework layer. This is only a mitigation; affected versions of `python-multipart` still parse multipart part headers without the default header count and header size limits.
AI Analysis
Technical Summary
A denial of service vulnerability (CVE-2026-42561) exists in python-multipart, a component used by Red Hat Satellite Lightspeed. The flaw allows a remote attacker to trigger excessive CPU consumption by sending multipart/form-data requests with an excessive number of part headers or a single very large header value. This leads to resource exhaustion and service disruption. The vulnerability is tracked under CWE-606 (Unchecked Input for Loop Condition) and CWE-770 (Allocation of Resources Without Limits or Throttling). Red Hat has published advisories describing the issue and made a new container image available as a Technology Preview, but no official fix has been released yet.
Potential Impact
The vulnerability can cause denial of service by exhausting CPU resources on affected systems running Red Hat Satellite Lightspeed. This results in service disruption and unavailability. There is no impact on confidentiality or integrity. The attack requires no privileges or user interaction and can be triggered remotely over the network.
Mitigation Recommendations
Red Hat has not released an official fix for this vulnerability yet. The advisory states a new container image is available as a Technology Preview but does not provide a patch. Users should monitor Red Hat Satellite documentation and advisories for updates. No specific mitigations are provided by Red Hat at this time. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Kimi cli: python-multipart has Denial of Service via unbounded multipart part headers (CVE-2026-42561)
Description
### Summary `python-multipart` has a denial of service vulnerability in multipart part header parsing. When parsing `multipart/form-data`, `MultipartParser` previously had no limit on the number of part headers or the size of an individual part header. An attacker could send a request with either many repeated headers without terminating the header block or a single very large header value, causing excessive CPU work before request rejection or completion. ### Impact Applications that parse attacker-controlled `multipart/form-data` with affected versions of `python-multipart` can experience CPU exhaustion. ASGI applications using Starlette, FastAPI, or other frameworks that invoke `python-multipart` may have worker or event-loop delays while processing malicious upload requests. ### Details The affected parser states are `HEADER_FIELD_START`, `HEADER_FIELD`, `HEADER_VALUE_START`, `HEADER_VALUE`, and `HEADER_VALUE_ALMOST_DONE`. The issue can be triggered by: - A multipart part with an oversized individual header value. - A multipart part with many repeated header lines or an unterminated header block. Both variants are addressed by enforcing default parser limits for maximum header count and maximum header size. ### Mitigation Upgrade to `python-multipart` `0.0.27` or later. If upgrading is not immediately possible, reduce exposure by enforcing request body size limits at the server, proxy, or framework layer. This is only a mitigation; affected versions of `python-multipart` still parse multipart part headers without the default header count and header size limits.
CVSS v3.1
Score 7.5high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A denial of service vulnerability (CVE-2026-42561) exists in python-multipart, a component used by Red Hat Satellite Lightspeed. The flaw allows a remote attacker to trigger excessive CPU consumption by sending multipart/form-data requests with an excessive number of part headers or a single very large header value. This leads to resource exhaustion and service disruption. The vulnerability is tracked under CWE-606 (Unchecked Input for Loop Condition) and CWE-770 (Allocation of Resources Without Limits or Throttling). Red Hat has published advisories describing the issue and made a new container image available as a Technology Preview, but no official fix has been released yet.
Potential Impact
The vulnerability can cause denial of service by exhausting CPU resources on affected systems running Red Hat Satellite Lightspeed. This results in service disruption and unavailability. There is no impact on confidentiality or integrity. The attack requires no privileges or user interaction and can be triggered remotely over the network.
Mitigation Recommendations
Red Hat has not released an official fix for this vulnerability yet. The advisory states a new container image is available as a Technology Preview but does not provide a patch. Users should monitor Red Hat Satellite documentation and advisories for updates. No specific mitigations are provided by Red Hat at this time. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:51219
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a757398bf8831d539d911a7
Added to database: 08/07/2026, 05:56:40 UTC
Last enriched: 09/12/2026, 06:46:53 UTC
Last updated: 09/22/2026, 13:47:45 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.