🛡️ CVE-2026-53537 on Ubuntu — python-multipart
Description
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Disposition (and Content-Type) headers with email.message.Message, which transparently applies RFC 2231/5987 decoding. The extended parameter syntax (filename*=charset'lang'value, name*=..., and the filename*0/filename*1 continuation form) is decoded and surfaced under the bare filename/name key, and overrides the plain parameter when both are present. RFC 7578 §4.2 explicitly forbids the filename* form in multipart/form-data. Components that follow RFC 7578, or that do not implement RFC 2231/5987 decoding for multipart/form-data (WAFs, proxies, gateways), may interpret such a header differently. An attacker can exploit that difference to smuggle a different field name or filename past an upstream inspector to the backend. This vulnerability is fixed in 0.0.30.
Distribution advisory
This page covers CVE-2026-53537 as tracked by Ubuntu, for the package python-multipart. No fixed version has been recorded for this distribution yet.
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity low, availability none.
Affected software
UBUNTU-CVE-2026-53537 is recorded against 1 package.
- python-multipart
Timeline and source
Published on 22 June 2026 and last revised on 29 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| python-multipart | — | — |
References
Similar Threats
- Unknown CLSA-2025-1758586346
- Unknown CLSA-2026-1769645547
- Unknown CLSA-2026-1781571262
- Unknown CLSA-2026-1782781170
- Unknown CLSA-2026-1782954025
More UBUNTU CVE 2026 advisories
Browse all of UBUNTU CVE 2026 in the advisory index.
- UBUNTU-CVE-2026-53492
- UBUNTU-CVE-2026-53500
- UBUNTU-CVE-2026-53501
- UBUNTU-CVE-2026-53502
- UBUNTU-CVE-2026-53503
- UBUNTU-CVE-2026-53504
- UBUNTU-CVE-2026-53505
- UBUNTU-CVE-2026-53511
- UBUNTU-CVE-2026-53538
- UBUNTU-CVE-2026-53539
- UBUNTU-CVE-2026-53540
- UBUNTU-CVE-2026-53550
- UBUNTU-CVE-2026-53583
- UBUNTU-CVE-2026-53584
- UBUNTU-CVE-2026-53585
- UBUNTU-CVE-2026-53586
Free Vulnerability Check
Is your site affected by UBUNTU-CVE-2026-53537?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against UBUNTU-CVE-2026-53537 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.