[Git][security-tracker-team/security-tracker][master] Track fixes for python-multipart issues via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 09:41:44 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0ecc50b8 by Salvatore Bonaccorso at 2026-09-25T10:41:07+02:00
Track fixes for python-multipart issues via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -105460,7 +105460,7 @@ CVE-2026-53550 (js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 a
 	[bullseye] - node-js-yaml <postponed> (Minor issue)
 	NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-h67p-54hq-rp68
 CVE-2026-53540 (Python-Multipart is a streaming multipart parser for Python. Prior to  ...)
-	- python-multipart <unfixed> (bug #1140628)
+	- python-multipart 0.0.32-1 (bug #1140628)
 	[trixie] - python-multipart <no-dsa> (Minor issue)
 	[bookworm] - python-multipart <postponed> (Minor issue; negative Content-Length unvalidated in parse_form(), which starlette/fastapi do not use)
 	[bullseye] - python-multipart <postponed> (Minor issue; negative Content-Length unvalidated in parse_form(), which starlette/fastapi do not use)
@@ -105468,21 +105468,21 @@ CVE-2026-53540 (Python-Multipart is a streaming multipart parser for Python. Pri
 	NOTE: https://github.com/Kludex/python-multipart/pull/297
 	NOTE: Fixed by: https://github.com/Kludex/python-multipart/commit/c814948acf509cef7881fa75c969969b19239bbf (0.0.31)
 CVE-2026-53539 (Python-Multipart is a streaming multipart parser for Python. Prior to  ...)
-	- python-multipart <unfixed> (bug #1140628)
+	- python-multipart 0.0.32-1 (bug #1140628)
 	[trixie] - python-multipart <no-dsa> (Minor issue)
 	[bookworm] - python-multipart <postponed> (Minor issue; quadratic separator scan in QuerystringParser on ';'-separated urlencoded bodies)
 	[bullseye] - python-multipart <postponed> (Minor issue; quadratic separator scan in QuerystringParser on ';'-separated urlencoded bodies)
 	NOTE: https://github.com/Kludex/python-multipart/security/advisories/GHSA-5rvq-cxj2-64vf
 	NOTE: Fixed by: https://github.com/Kludex/python-multipart/commit/d69df35cd2cad9c72794c2c340db646afae957d8 (0.0.30)
 CVE-2026-53538 (Python-Multipart is a streaming multipart parser for Python. Prior to  ...)
-	- python-multipart <unfixed> (bug #1140628)
+	- python-multipart 0.0.32-1 (bug #1140628)
 	[trixie] - python-multipart <no-dsa> (Minor issue)
 	[bookworm] - python-multipart <postponed> (Minor issue; parser differential, QuerystringParser accepts ';' as a urlencoded field separator)
 	[bullseye] - python-multipart <postponed> (Minor issue; parser differential, QuerystringParser accepts ';' as a urlencoded field separator)
 	NOTE: https://github.com/Kludex/python-multipart/security/advisories/GHSA-6jv3-5f52-599m
 	NOTE: Fixed by: https://github.com/Kludex/python-multipart/commit/d69df35cd2cad9c72794c2c340db646afae957d8 (0.0.30)
 CVE-2026-53537 (Python-Multipart is a streaming multipart parser for Python. Prior to  ...)
-	- python-multipart <unfixed> (bug #1140628)
+	- python-multipart 0.0.32-1 (bug #1140628)
 	[trixie] - python-multipart <no-dsa> (Minor issue)
 	[bookworm] - python-multipart <not-affected> (parse_options_header uses a custom regex with no RFC 2231/5987 decoding; email.message.Message introduced in 0.0.7)
 	[bullseye] - python-multipart <not-affected> (parse_options_header uses a custom regex with no RFC 2231/5987 decoding; email.message.Message introduced in 0.0.7)
@@ -131481,7 +131481,7 @@ CVE-2026-42577 (Netty is an asynchronous, event-driven network application frame
 	NOTE: https://github.com/netty/netty/pull/16689
 	NOTE: Fixed by: https://github.com/netty/netty/commit/0ec3d97fab376e243d328ac95fbd288ba0f6e22d (netty-4.2.13.Final)
 CVE-2026-42561 (Python-Multipart is a streaming multipart parser for Python. Prior to  ...)
-	- python-multipart <unfixed> (bug #1136702)
+	- python-multipart 0.0.32-1 (bug #1136702)
 	[trixie] - python-multipart <no-dsa> (Minor issue)
 	[bookworm] - python-multipart <no-dsa> (Minor issue)
 	[bullseye] - python-multipart <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ecc50b8f23418cb8957103918b4c6409297c8fe

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ecc50b8f23418cb8957103918b4c6409297c8fe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/a49b65fe/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list