<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:25:09.638511+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-01435</id>
    <title>bdu:2025-01435</title>
    <updated>2026-10-03T17:25:10.002388+00:00</updated>
    <content>bdu:2025-01435</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-01435"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-datasette-cve-2024-24762</id>
    <title>BREW-datasette-CVE-2024-24762 — python-multipart vulnerable to Content-Type Header ReDoS</title>
    <updated>2026-10-03T17:25:10.002432+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: datasette</p>
<p>### Summary</p>
<p>When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options.</p>
<p>An attacker could send a custom-made `Content-Type` option that is very difficult for the RegEx to process, consuming CPU resources and stalling indefinitely (minutes or more) while holding the main event loop. This means that process can't handle any more requests.</p>
<p>This can create a ReDoS (Regular expression Denial of Service): https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS</p>
<p>This only applies when the app uses form data, parsed with `python-multipart`.</p>
<p>### Details</p>
<p>A regular HTTP `Content-Type` header could look like:</p>
<p>```
Content-Type: text/html; charset=utf-8
```</p>
<p>`python-multipart` parses the option with this RegEx: https://github.com/andrew-d/python-multipart/blob/d3d16dae4b061c34fe9d3c9081d9800c49fc1f7a/multipart/multipart.py#L72-L74</p>
<p>A custom option could be made and sent to the server to break it with:</p>
<p>```
Content-Type: application/x-www-form-urlencoded; !=\"\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
```</p>
<p>### PoC</p>
<p>Create a simple WSGI application, that just parses the `Content-Type`, and run it with `python main.py`:</p>
<p>```Python
# main.py
from wsgiref.simple_server import make_server
from wsgiref.vali…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-datasette-cve-2024-24762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199</id>
    <title>certfr-2024-avi-0199 — De multiples vulnérabilités ont été découvertes dans &lt;span
class="textit"&gt;les produits IBM&lt;/span&gt;. Certaines d'entre el…</title>
    <updated>2026-10-03T17:25:10.002508+00:00</updated>
    <content>certfr-2024-avi-0199</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2024-avi-0199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-238693</id>
    <title>EUVD-2026-238693</title>
    <updated>2026-10-03T17:25:10.002539+00:00</updated>
    <content>EUVD-2026-238693</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-238693"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2024-24762</id>
    <title>fkie_cve-2024-24762</title>
    <updated>2026-10-03T17:25:10.002558+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. An attacker could send a custom-made `Content-Type` option that is very difficult for the RegEx to process, consuming CPU resources and stalling indefinitely (minutes or more) while holding the main event loop. This means that process can't handle any more requests, leading to regular expression denial of service. This vulnerability has been patched in version 0.0.7.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2024-24762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-2jv5-9r88-3w3p</id>
    <title>GHSA-2jv5-9r88-3w3p — python-multipart vulnerable to Content-Type Header ReDoS</title>
    <updated>2026-10-03T17:25:10.002600+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: python-multipart</p>
<p>### Summary</p>
<p>When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options.</p>
<p>An attacker could send a custom-made `Content-Type` option that is very difficult for the RegEx to process, consuming CPU resources and stalling indefinitely (minutes or more) while holding the main event loop. This means that process can't handle any more requests.</p>
<p>This can create a ReDoS (Regular expression Denial of Service): https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS</p>
<p>This only applies when the app uses form data, parsed with `python-multipart`.</p>
<p>### Details</p>
<p>A regular HTTP `Content-Type` header could look like:</p>
<p>```
Content-Type: text/html; charset=utf-8
```</p>
<p>`python-multipart` parses the option with this RegEx: https://github.com/andrew-d/python-multipart/blob/d3d16dae4b061c34fe9d3c9081d9800c49fc1f7a/multipart/multipart.py#L72-L74</p>
<p>A custom option could be made and sent to the server to break it with:</p>
<p>```
Content-Type: application/x-www-form-urlencoded; !=\"\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
```</p>
<p>### PoC</p>
<p>Create a simple WSGI application, that just parses the `Content-Type`, and run it with `python main.py`:</p>
<p>```Python
# main.py
from wsgiref.simple_server import make_server
from wsgiref.vali…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-2jv5-9r88-3w3p"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2024-24762</id>
    <title>gsd-2024-24762</title>
    <updated>2026-10-03T17:25:10.002742+00:00</updated>
    <content>gsd-2024-24762</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2024-24762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13664-1</id>
    <title>openSUSE-SU-2024:13664-1 — python310-python-multipart-0.0.7-1.1 on GA media</title>
    <updated>2026-10-03T17:25:10.002772+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>python310-python-multipart-0.0.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13664-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2024-38</id>
    <title>PYSEC-2024-38</title>
    <updated>2026-10-03T17:25:10.002803+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: fastapi</p>
<p>FastAPI is a web framework for building APIs with Python 3.8+ based on standard Python type hints. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. An attacker could send a custom-made `Content-Type` option that is very difficult for the RegEx to process, consuming CPU resources and stalling indefinitely (minutes or more) while holding the main event loop. This means that process can't handle any more requests. It's a ReDoS(Regular expression Denial of Service), it only applies to those reading form data, using `python-multipart`. This vulnerability has been patched in version 0.109.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2024-38"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24762</id>
    <title>UBUNTU-CVE-2024-24762</title>
    <updated>2026-10-03T17:25:10.002851+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:22.04:LTS: python-multipart</p>
<p>`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. An attacker could send a custom-made `Content-Type` option that is very difficult for the RegEx to process, consuming CPU resources and stalling indefinitely (minutes or more) while holding the main event loop. This means that process can't handle any more requests, leading to regular expression denial of service. This vulnerability has been patched in version 0.0.7.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-24762"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0592</id>
    <title>WID-SEC-W-2024-0592 — IBM App Connect Enterprise: Schwachstelle ermöglicht Denial of Service</title>
    <updated>2026-10-03T17:25:10.002889+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM App Connect Enterprise ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2024-0592"/>
  </entry>
</feed>
