[Git][security-tracker-team/security-tracker][master] Track fixes for python-multipart issues via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 25 09:41:44 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0ecc50b8 by Salvatore Bonaccorso at 2026-09-25T10:41:07+02:00
Track fixes for python-multipart issues via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -105460,7 +105460,7 @@ CVE-2026-53550 (js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 a
[bullseye] - node-js-yaml <postponed> (Minor issue)
NOTE: https://github.com/nodeca/js-yaml/security/advisories/GHSA-h67p-54hq-rp68
CVE-2026-53540 (Python-Multipart is a streaming multipart parser for Python. Prior to ...)
- - python-multipart <unfixed> (bug #1140628)
+ - python-multipart 0.0.32-1 (bug #1140628)
[trixie] - python-multipart <no-dsa> (Minor issue)
[bookworm] - python-multipart <postponed> (Minor issue; negative Content-Length unvalidated in parse_form(), which starlette/fastapi do not use)
[bullseye] - python-multipart <postponed> (Minor issue; negative Content-Length unvalidated in parse_form(), which starlette/fastapi do not use)
@@ -105468,21 +105468,21 @@ CVE-2026-53540 (Python-Multipart is a streaming multipart parser for Python. Pri
NOTE: https://github.com/Kludex/python-multipart/pull/297
NOTE: Fixed by: https://github.com/Kludex/python-multipart/commit/c814948acf509cef7881fa75c969969b19239bbf (0.0.31)
CVE-2026-53539 (Python-Multipart is a streaming multipart parser for Python. Prior to ...)
- - python-multipart <unfixed> (bug #1140628)
+ - python-multipart 0.0.32-1 (bug #1140628)
[trixie] - python-multipart <no-dsa> (Minor issue)
[bookworm] - python-multipart <postponed> (Minor issue; quadratic separator scan in QuerystringParser on ';'-separated urlencoded bodies)
[bullseye] - python-multipart <postponed> (Minor issue; quadratic separator scan in QuerystringParser on ';'-separated urlencoded bodies)
NOTE: https://github.com/Kludex/python-multipart/security/advisories/GHSA-5rvq-cxj2-64vf
NOTE: Fixed by: https://github.com/Kludex/python-multipart/commit/d69df35cd2cad9c72794c2c340db646afae957d8 (0.0.30)
CVE-2026-53538 (Python-Multipart is a streaming multipart parser for Python. Prior to ...)
- - python-multipart <unfixed> (bug #1140628)
+ - python-multipart 0.0.32-1 (bug #1140628)
[trixie] - python-multipart <no-dsa> (Minor issue)
[bookworm] - python-multipart <postponed> (Minor issue; parser differential, QuerystringParser accepts ';' as a urlencoded field separator)
[bullseye] - python-multipart <postponed> (Minor issue; parser differential, QuerystringParser accepts ';' as a urlencoded field separator)
NOTE: https://github.com/Kludex/python-multipart/security/advisories/GHSA-6jv3-5f52-599m
NOTE: Fixed by: https://github.com/Kludex/python-multipart/commit/d69df35cd2cad9c72794c2c340db646afae957d8 (0.0.30)
CVE-2026-53537 (Python-Multipart is a streaming multipart parser for Python. Prior to ...)
- - python-multipart <unfixed> (bug #1140628)
+ - python-multipart 0.0.32-1 (bug #1140628)
[trixie] - python-multipart <no-dsa> (Minor issue)
[bookworm] - python-multipart <not-affected> (parse_options_header uses a custom regex with no RFC 2231/5987 decoding; email.message.Message introduced in 0.0.7)
[bullseye] - python-multipart <not-affected> (parse_options_header uses a custom regex with no RFC 2231/5987 decoding; email.message.Message introduced in 0.0.7)
@@ -131481,7 +131481,7 @@ CVE-2026-42577 (Netty is an asynchronous, event-driven network application frame
NOTE: https://github.com/netty/netty/pull/16689
NOTE: Fixed by: https://github.com/netty/netty/commit/0ec3d97fab376e243d328ac95fbd288ba0f6e22d (netty-4.2.13.Final)
CVE-2026-42561 (Python-Multipart is a streaming multipart parser for Python. Prior to ...)
- - python-multipart <unfixed> (bug #1136702)
+ - python-multipart 0.0.32-1 (bug #1136702)
[trixie] - python-multipart <no-dsa> (Minor issue)
[bookworm] - python-multipart <no-dsa> (Minor issue)
[bullseye] - python-multipart <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ecc50b8f23418cb8957103918b4c6409297c8fe
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ecc50b8f23418cb8957103918b4c6409297c8fe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/a49b65fe/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list