VDB
Sign up
HIGH7.5

PYSEC-2026-2670

multipart vulnerable to ReDoS in `parse_options_header()`

Quick fix

PYSEC-2026-2670 — multipart: upgrade to the fixed version with the command below.

pip install --upgrade 'multipart>=1.2.2'

Details

## Summary

The `parse_options_header()` function in `multipart.py` uses a regular expression with an *ambiguous alternation*, which can cause *exponential backtracking (ReDoS)* when parsing maliciously crafted HTTP or multipart segment headers. This can be abused for **denial of service (DoS)** attacks against web applications using this library to parse request headers or `multipart/form-data` streams.

## Impact

Any WSGI or ASGI application using `multipart.parse_form_data()` directly or indirectly (e.g. while parsing `multipart/form-data` streams) is vulnerable. The slow-down is significant enough to block request handling threads for multiple seconds per request.

## Affected versions

All versions up to and including `1.3.0` are affected. The issue is fixed in `1.2.2`, `1.3.1` and `1.4.0-dev`.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/multipart
Introduced in: 0Fixed in: 1.2.2
Fixpip install --upgrade 'multipart>=1.2.2'

References