CVE-2026-53538Fastapiexpert · Python-multipart
Vulnerability data via NVD (ingested)
Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field separator in application/x-www-form-urlencoded bodies, in addition to &. The WHATWG URL standard, modern browsers, and Python's urllib.parse (since the CVE-2021-23336 fix) treat only & as a separator. This creates a parser differential: the same bytes are tokenized into different fields than a WHATWG compliant intermediary would produce, allowing an attacker to smuggle extra form fields past an upstream body inspecting component. This vulnerability is fixed in 0.0.30.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-53538product:"Fastapiexpert Python-multipart"http.html:"Python-multipart"More intel sources (5)
vuln:CVE-2026-53538vulnerabilities.cve_id: CVE-2026-53538CVE-2026-53538CVE-2026-53538"CVE-2026-53538" exploit -site:nvd.nist.gov