Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Fedora 43 python-multipart Update 1.3.1 DoS Fix FEDORA-2026-5c75eb75d1

fedora
Calendar Grey March 25, 2026
Dist Fedora Esm H88
Update to Fedora 43 python-multipart 1.3.1 fixes CVE-2026-28356 denial of service risk via HTTP headers.
Update to version 1.3.1 to fix CVE-2026-28356.

Summary

This module provides a fast incremental non-blocking parser for

multipart/form-data [HTML5, RFC7578], as well as blocking alternatives for

easier use in WSGI or CGI applications.

Update Information:

Update to version 1.3.1 to fix CVE-2026-28356.

Change Log

* Mon Mar 16 2026 Carl George - 1.3.1-1 - Update to version 1.3.1 rhbz#2443306 - Fixes CVE-2026-28356 rhbz#2447328

References


[ 1 ] Bug #2447328 - CVE-2026-28356 python-multipart: denial of service via maliciously crafted HTTP or multipart segment headers [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2447328

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5c75eb75d1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: python-multipart
Product: Fedora 43
Version: 1.3.1
Release: 1.fc43
Summary: Parser for multipart/form-data

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here