Alerts This Week
Warning Icon 1 1,394
Alerts This Week
Warning Icon 1 1,394

SUSE Python Multipart Important Denial of Service Fix 2026-22372-1

suse
Calendar Grey July 1, 2026
Dist Suse Esm H88
This security advisory details important updates for python-python-multipart that fix critical issues including denial of service.
An update that solves four vulnerabilities can now be installed.

Summary

## This update for python-python-multipart fixes the following issues * CVE-2026-53537: multipart/form-data with extended parameters can lead to file or parameter smuggling (bsc#1268506). * CVE-2026-53538: urlencoded requests containing semicolons can lead to form field smuggling (bsc#1268496). * CVE-2026-53539: small crafted body can cause a denial of service (bsc#1268500). * CVE-2026-53540: crafted request buffers can lead to degrading availability (bsc#1268488). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1088=1 * SUSE Linux Enterprise Server for SAP applications 16.0

References

* bsc#1268488

* bsc#1268496

* bsc#1268500

* bsc#1268506

Cross-

* CVE-2026-53537

* CVE-2026-53538

* CVE-2026-53539

* CVE-2026-53540

CVSS scores:

* CVE-2026-53537 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2026-53537 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-53537 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-53537 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-53538 ( SUSE ): 6.3

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2026-53538 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-53538 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-53539 ( SUSE ): 8.7

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:22372-1
Release Date: 2026-06-26T08:00:10Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here