
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-28356 is a Regular Expression Denial of Service (ReDoS) vulnerability in the Python multipart library, specifically in the parse_options_header() function within multipart.py. The function uses a regular expression with an ambiguous alternation that can cause exponential backtracking when processing maliciously crafted HTTP or multipart segment headers. All versions up to and including 1.3.0 are affected; fixed versions are 1.2.2, 1.3.1, and 1.4.0-dev. It was disclosed on March 12, 2026, with a CVSS v3.1 base score of 7.5 (High) (Github Advisory, GitHub Security Advisory).
The root cause is classified as CWE-1333 (Inefficient Regular Expression Complexity), mapped to CAPEC-492 (Regular Expression Exponential Blowup). The vulnerable parse_options_header() function in multipart.py contains a regex with an ambiguous alternation pattern; when an attacker supplies a specially crafted header value, the regex engine enters exponential backtracking, consuming excessive CPU cycles. The attack vector is network-based, requires no authentication or user interaction, and targets any WSGI or ASGI application that calls multipart.parse_form_data() directly or indirectly — for example, when parsing multipart/form-data streams or HTTP request headers (Github Advisory, GitHub Security Advisory).
Successful exploitation causes a high availability impact through resource exhaustion, with the slowdown significant enough to block request handling threads for multiple seconds per malicious request. There is no confidentiality or integrity impact — the vulnerability is purely a denial-of-service condition. Web applications that accept file uploads or multipart form submissions from untrusted users are most at risk, as a sustained attack could render the service completely unavailable (Github Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.71–0.86%, indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection plugins are available via Tenable Nessus (plugin IDs 301999 and 303583) and Qualys (ID 6633237).
multipart library (versions ≤ 1.3.0) by inspecting HTTP response headers, error messages, or open-source dependency manifests (e.g., requirements.txt, pyproject.toml) for the multipart package.Content-Type or multipart segment header value specifically designed to trigger exponential backtracking in the vulnerable regex within parse_options_header() — for example, a long string with repeated characters that match the ambiguous alternation pattern.Content-Type: multipart/form-data; boundary=... and a malicious parameter value) to any endpoint that parses multipart data or HTTP headers using the vulnerable library.multipart/form-data with abnormally long or malformed Content-Type or segment headers; requests with headers containing repeated special characters or unusual boundary values.gunicorn, uvicorn, uwsgi) without a corresponding increase in legitimate traffic; worker threads or processes becoming unresponsive or timing out.Upgrade the multipart Python library to version 1.2.2, 1.3.1, or 1.4.0-dev or later, which contain the fixed regex implementation (Github Advisory). Red Hat has issued errata RHSA-2026:5809, RHSA-2026:6761, and RHSA-2026:6762 for affected Red Hat products (Red Hat Errata). As a short-term workaround where patching is not immediately possible, consider placing a web application firewall (WAF) or reverse proxy in front of affected services to limit the size and complexity of incoming Content-Type and multipart headers from untrusted sources.
The library maintainer (defnull) published the security advisory on GitHub on March 12, 2026, and acknowledged the fix in versions 1.2.2, 1.3.1, and 1.4.0-dev (GitHub Security Advisory). The maintainer also posted about the issue on Mastodon (chaos.social). Red Hat tracked the issue via Bugzilla with high severity and subsequently released multiple errata. Debian and Fedora also issued package updates, and the vulnerability received coverage from Linux security news outlets including linuxsecurity.com and pro-linux.de.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."