← Back to CVE List
Vulnerability Intelligence Report
Python-Multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service

CVE-2026-53539

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlencoded bodies, QuerystringParser located the field separator with a two step lookup: it first scanned the entire remaining buffer for &, and only when no & existed anywhere ahead did it fall back to scanning for ;. For a body that uses ; as the separator and contains no &, every field iteration performed a full failed & scan over the entire remaining buffer before locating the nearby ;. With N semicolon separated fields in a chunk of size B, this yields O(B^2) byte comparisons per chunk. An attacker can submit a small crafted body of the form a;a;a;... and cause the parser to spend seconds of CPU per request. A handful of concurrent requests can exhaust worker processes. This vulnerability is fixed in 0.0.30.

No Active Exploit Signals
CVSS Base Score
7.5
HIGH
Exploitability:3.9
Impact Score:3.6
EPSS Probability:0.26%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-400 ↗CWE-400: Uncontrolled Resource Consumption
CWE-407 ↗CWE-407: Inefficient Algorithmic Complexity

Affected Products & Versions

Vendor Product Affected Versions
Kludex python-multipart < 0.0.30 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.263%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-06-09T18:13:07
Published2026-06-22T16:55:42
Last Updated2026-06-23T16:08:36

LINK COPIED TO CLIPBOARD