{"id":"openSUSE-SU-2026:20846-1","summary":"Security update for python-python-multipart","details":"This update for python-python-multipart fixes the following issues\n\n- CVE-2026-40347: crafted `multipart/form-data` can cause a denial of service (bsc#1262403).\n- CVE-2026-42561: denial of service vulnerability in multipart part header parsing (bsc#1265250).\n","modified":"2026-06-02T18:24:30.695342324Z","published":"2026-05-29T14:27:24Z","related":["CVE-2026-40347","CVE-2026-42561"],"upstream":["CVE-2026-40347","CVE-2026-42561"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262403"},{"type":"REPORT","url":"https://bugzilla.suse.com/1265250"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40347"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42561"}],"schema_version":"1.7.5"}