UBUNTU-CVE-2026-24486

Source
https://ubuntu.com/security/CVE-2026-24486
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-24486.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-24486
Upstream
Published
2026-01-27T00:00:00Z
Modified
2026-01-27T13:00:56.547491Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options UPLOAD_DIR and UPLOAD_KEEP_FILENAME=True. An attacker can write uploaded files to arbitrary locations on the filesystem by crafting a malicious filename. Users should upgrade to version 0.0.22 to receive a patch or, as a workaround, avoid using UPLOAD_KEEP_FILENAME=True in project configurations.

References

Affected packages

Ubuntu:22.04:LTS / python-multipart

Package

Name
python-multipart
Purl
pkg:deb/ubuntu/python-multipart@0.0.5-2?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.0.5-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-multipart",
            "binary_version": "0.0.5-2"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-24486.json"

Ubuntu:24.04:LTS / python-multipart

Package

Name
python-multipart
Purl
pkg:deb/ubuntu/python-multipart@0.0.9-1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.0.5-3
0.0.6-1
0.0.9-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-multipart",
            "binary_version": "0.0.9-1"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-24486.json"

Ubuntu:25.10 / python-multipart

Package

Name
python-multipart
Purl
pkg:deb/ubuntu/python-multipart@0.0.20-1?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

0.*

0.0.20-1

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "python3-python-multipart",
            "binary_version": "0.0.20-1"
        }
    ]
}

Database specific

source

"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-24486.json"