This module provides a fast incremental non-blocking parser for
multipart/form-data [HTML5, RFC7578], as well as blocking alternatives for
easier use in WSGI or CGI applications.
Update Information:
Update to version 1.3.1 to fix CVE-2026-28356.
* Mon Mar 16 2026 Carl George
[ 1 ] Bug #2447328 - CVE-2026-28356 python-multipart: denial of service via maliciously crafted HTTP or multipart segment headers [fedora-43]
https://bugzilla.redhat.com/show_bug.cgi?id=2447328
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5c75eb75d1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.