CVE-2026-28356: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-28356 is a Regular Expression Denial of Service (ReDoS) vulnerability in the Python multipart library, specifically in the parse_options_header() function within multipart.py. The function uses a regular expression with an ambiguous alternation that can cause exponential backtracking when processing maliciously crafted HTTP or multipart segment headers. All versions up to and including 1.3.0 are affected; fixed versions are 1.2.2, 1.3.1, and 1.4.0-dev. It was disclosed on March 12, 2026, with a CVSS v3.1 base score of 7.5 (High) (Github Advisory, GitHub Security Advisory).

Technical details

The root cause is classified as CWE-1333 (Inefficient Regular Expression Complexity), mapped to CAPEC-492 (Regular Expression Exponential Blowup). The vulnerable parse_options_header() function in multipart.py contains a regex with an ambiguous alternation pattern; when an attacker supplies a specially crafted header value, the regex engine enters exponential backtracking, consuming excessive CPU cycles. The attack vector is network-based, requires no authentication or user interaction, and targets any WSGI or ASGI application that calls multipart.parse_form_data() directly or indirectly — for example, when parsing multipart/form-data streams or HTTP request headers (Github Advisory, GitHub Security Advisory).

Impact

Successful exploitation causes a high availability impact through resource exhaustion, with the slowdown significant enough to block request handling threads for multiple seconds per malicious request. There is no confidentiality or integrity impact — the vulnerability is purely a denial-of-service condition. Web applications that accept file uploads or multipart form submissions from untrusted users are most at risk, as a sustained attack could render the service completely unavailable (Github Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Github Advisory). The EPSS score is approximately 0.71–0.86%, indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection plugins are available via Tenable Nessus (plugin IDs 301999 and 303583) and Qualys (ID 6633237).

Exploitation steps

  1. Reconnaissance: Identify web applications using the Python multipart library (versions ≤ 1.3.0) by inspecting HTTP response headers, error messages, or open-source dependency manifests (e.g., requirements.txt, pyproject.toml) for the multipart package.
  2. Craft malicious header: Construct an HTTP request with a Content-Type or multipart segment header value specifically designed to trigger exponential backtracking in the vulnerable regex within parse_options_header() — for example, a long string with repeated characters that match the ambiguous alternation pattern.
  3. Send the request: Submit the crafted HTTP POST request (e.g., with Content-Type: multipart/form-data; boundary=... and a malicious parameter value) to any endpoint that parses multipart data or HTTP headers using the vulnerable library.
  4. Trigger DoS: The regex engine enters exponential backtracking, consuming CPU resources and blocking the request handling thread for multiple seconds. Repeating this with concurrent requests can exhaust server threads and cause a full denial of service (Github Advisory, GitHub Security Advisory).

Indicators of compromise

  • Network: Unusual volume of HTTP POST requests to endpoints accepting multipart/form-data with abnormally long or malformed Content-Type or segment headers; requests with headers containing repeated special characters or unusual boundary values.
  • Logs: Web server or application logs showing requests with extremely long processing times (multiple seconds) for multipart parsing endpoints; repeated requests from the same source IP targeting form upload endpoints.
  • Process: Elevated CPU utilization on the Python web application process (e.g., gunicorn, uvicorn, uwsgi) without a corresponding increase in legitimate traffic; worker threads or processes becoming unresponsive or timing out.

Mitigation and workarounds

Upgrade the multipart Python library to version 1.2.2, 1.3.1, or 1.4.0-dev or later, which contain the fixed regex implementation (Github Advisory). Red Hat has issued errata RHSA-2026:5809, RHSA-2026:6761, and RHSA-2026:6762 for affected Red Hat products (Red Hat Errata). As a short-term workaround where patching is not immediately possible, consider placing a web application firewall (WAF) or reverse proxy in front of affected services to limit the size and complexity of incoming Content-Type and multipart headers from untrusted sources.

Community reactions

The library maintainer (defnull) published the security advisory on GitHub on March 12, 2026, and acknowledged the fix in versions 1.2.2, 1.3.1, and 1.4.0-dev (GitHub Security Advisory). The maintainer also posted about the issue on Mastodon (chaos.social). Red Hat tracked the issue via Bugzilla with high severity and subsequently released multiple errata. Debian and Fedora also issued package updates, and the vulnerability received coverage from Linux security news outlets including linuxsecurity.com and pro-linux.de.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

multipart: 1.3.1-1

Fixed

trixie

multipart: 1.2.1-2+deb13u1

Fixed

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management