GHSA-p2m9-wcp5-6qw3 · Severity: high · Ecosystem: pip — multipart vulnerable to ReDoS in `parse_options_header()`
multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential backtracking (ReDoS) when parsing maliciously crafted HTTP or multipart segment headers. This can be abused for denial of service (DoS) attacks against web applications using this library to parse request headers or multipart/form-data streams. The issue is fixed in 1.2.2, 1.3.1 and 1.4.0-dev.
Conclusion & alert: CVE-2026-28356 is rated Moderate Risk (56.4/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.86%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-19 | 0.82% | 0.86% | +0.04% |
| 2 | 2026-04-13 | 0.71% | 0.82% | +0.11% |
| 3 | 2026-03-18 | — | 0.71% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-p2m9-wcp5-6qw3 · Severity: high · Ecosystem: pip — multipart vulnerable to ReDoS in `parse_options_header()`
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-28356 not yet assigned priority: Debian including 1 source packages (multipart), 3 status rows across 3 suites (forky, sid, trixie): resolved 3. | https://security-tracker.debian.org/tracker/CVE-2026-28356 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2026-28356 |
ubuntu
|
medium | CVE-2026-28356 medium priority: Ubuntu including 1 source packages (multipart), 4 status rows across 4 suites (jammy, noble, questing, upstream): DNE 2, needs-triage 1, released 1. | https://ubuntu.com/security/CVE-2026-28356 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||