{"document":{"aggregate_severity":{"namespace":"https://www.suse.com/support/security/rating/","text":"important"},"category":"csaf_vex","csaf_version":"2.0","distribution":{"text":"Copyright 2024 SUSE LLC. All rights reserved.","tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en","notes":[{"category":"summary","text":"SUSE CVE-2024-24762","title":"Title"},{"category":"description","text":"`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. An attacker could send a custom-made `Content-Type` option that is very difficult for the RegEx to process, consuming CPU resources and stalling indefinitely (minutes or more) while holding the main event loop. This means that process can't handle any more requests, leading to regular expression denial of service. This vulnerability has been patched in version 0.0.7.","title":"Description of the CVE"},{"category":"legal_disclaimer","text":"CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).","title":"Terms of use"}],"publisher":{"category":"vendor","contact_details":"https://www.suse.com/support/security/contact/","name":"SUSE Product Security Team","namespace":"https://www.suse.com/"},"references":[{"category":"external","summary":"CVE-2024-24762","url":"https://www.suse.com/security/cve/CVE-2024-24762"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1219603 for CVE-2024-24762","url":"https://bugzilla.suse.com/1219603"}],"title":"SUSE CVE CVE-2024-24762","tracking":{"current_release_date":"2026-03-12T09:00:34Z","generator":{"date":"2024-02-07T03:45:48Z","engine":{"name":"cve-database.git:bin/generate-csaf-vex.pl","version":"1"}},"id":"CVE-2024-24762","initial_release_date":"2024-02-07T03:45:48Z","revision_history":[{"date":"2024-02-07T03:45:48Z","number":"2","summary":"Current version"},{"date":"2024-02-09T03:00:31Z","number":"3","summary":"Current version"},{"date":"2024-07-03T03:38:23Z","number":"4","summary":"Current version"},{"date":"2024-08-02T02:18:15Z","number":"5","summary":"Current version"},{"date":"2025-01-01T01:28:26Z","number":"6","summary":"Current version"},{"date":"2025-02-14T05:26:36Z","number":"7","summary":"Current version"},{"date":"2025-02-16T05:19:33Z","number":"8","summary":"Current version"},{"date":"2025-03-15T05:31:14Z","number":"9","summary":"Current version"},{"date":"2025-04-24T14:54:09Z","number":"10","summary":"Current version"},{"date":"2025-11-03T02:10:19Z","number":"11","summary":"Current version"},{"date":"2026-01-23T02:25:23Z","number":"12","summary":"unknown changes"},{"date":"2026-03-12T09:00:34Z","number":"13","summary":"unknown changes"}],"status":"interim","version":"13"}},"product_tree":{"branches":[{"branches":[{"branches":[{"category":"product_name","name":"SUSE Linux Enterprise Server 16.0","product":{"name":"SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0","product_identification_helper":{"cpe":"cpe:/o:suse:sles:16.0"}}},{"category":"product_name","name":"openSUSE Leap 15.6","product":{"name":"openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6","product_identification_helper":{"cpe":"cpe:/o:opensuse:leap:15.6"}}},{"category":"product_name","name":"openSUSE Tumbleweed","product":{"name":"openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed","product_identification_helper":{"cpe":"cpe:/o:opensuse:tumbleweed"}}},{"category":"product_version","name":"python-python-multipart","product":{"name":"python-python-multipart","product_id":"python-python-multipart","product_identification_helper":{"purl":"pkg:rpm/suse/python-python-multipart@"}}},{"category":"product_version","name":"python310-fastapi-0.109.1-1.1","product":{"name":"python310-fastapi-0.109.1-1.1","product_id":"python310-fastapi-0.109.1-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python310-fastapi@0.109.1-1.1"}}},{"category":"product_version","name":"python310-python-multipart-0.0.7-1.1","product":{"name":"python310-python-multipart-0.0.7-1.1","product_id":"python310-python-multipart-0.0.7-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python310-python-multipart@0.0.7-1.1"}}},{"category":"product_version","name":"python311-fastapi-0.109.1-1.1","product":{"name":"python311-fastapi-0.109.1-1.1","product_id":"python311-fastapi-0.109.1-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python311-fastapi@0.109.1-1.1?upstream=python-fastapi-0.109.1-1.1.src.rpm"}}},{"category":"product_version","name":"python311-python-multipart","product":{"name":"python311-python-multipart","product_id":"python311-python-multipart","product_identification_helper":{"purl":"pkg:rpm/suse/python311-python-multipart@?upstream=python-python-multipart.src.rpm"}}},{"category":"product_version","name":"python311-python-multipart-0.0.7-1.1","product":{"name":"python311-python-multipart-0.0.7-1.1","product_id":"python311-python-multipart-0.0.7-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python311-python-multipart@0.0.7-1.1?upstream=python-python-multipart-0.0.7-1.1.src.rpm"}}},{"category":"product_version","name":"python312-fastapi-0.109.1-1.1","product":{"name":"python312-fastapi-0.109.1-1.1","product_id":"python312-fastapi-0.109.1-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python312-fastapi@0.109.1-1.1"}}},{"category":"product_version","name":"python312-python-multipart-0.0.7-1.1","product":{"name":"python312-python-multipart-0.0.7-1.1","product_id":"python312-python-multipart-0.0.7-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python312-python-multipart@0.0.7-1.1"}}},{"category":"product_version","name":"python313-fastapi-0.115.8-160000.2.2","product":{"name":"python313-fastapi-0.115.8-160000.2.2","product_id":"python313-fastapi-0.115.8-160000.2.2","product_identification_helper":{"purl":"pkg:rpm/suse/python313-fastapi@0.115.8-160000.2.2?upstream=python-fastapi-0.115.8-160000.2.2.src.rpm"}}},{"category":"product_version","name":"python313-python-multipart-0.0.20-160000.2.2","product":{"name":"python313-python-multipart-0.0.20-160000.2.2","product_id":"python313-python-multipart-0.0.20-160000.2.2","product_identification_helper":{"purl":"pkg:rpm/suse/python313-python-multipart@0.0.20-160000.2.2?upstream=python-python-multipart-0.0.20-160000.2.2.src.rpm"}}},{"category":"product_version","name":"python39-fastapi-0.109.1-1.1","product":{"name":"python39-fastapi-0.109.1-1.1","product_id":"python39-fastapi-0.109.1-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python39-fastapi@0.109.1-1.1"}}},{"category":"product_version","name":"python39-python-multipart-0.0.7-1.1","product":{"name":"python39-python-multipart-0.0.7-1.1","product_id":"python39-python-multipart-0.0.7-1.1","product_identification_helper":{"purl":"pkg:rpm/suse/python39-python-multipart@0.0.7-1.1"}}}],"category":"product_family","name":"SUSE Linux Enterprise"}],"category":"vendor","name":"SUSE"}],"relationships":[{"category":"default_component_of","full_product_name":{"name":"python313-fastapi-0.115.8-160000.2.2 as component of SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0:python313-fastapi-0.115.8-160000.2.2"},"product_reference":"python313-fastapi-0.115.8-160000.2.2","relates_to_product_reference":"SUSE Linux Enterprise Server 16.0"},{"category":"default_component_of","full_product_name":{"name":"python313-python-multipart-0.0.20-160000.2.2 as component of SUSE Linux Enterprise Server 16.0","product_id":"SUSE Linux Enterprise Server 16.0:python313-python-multipart-0.0.20-160000.2.2"},"product_reference":"python313-python-multipart-0.0.20-160000.2.2","relates_to_product_reference":"SUSE Linux Enterprise Server 16.0"},{"category":"default_component_of","full_product_name":{"name":"python310-fastapi-0.109.1-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python310-fastapi-0.109.1-1.1"},"product_reference":"python310-fastapi-0.109.1-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python310-python-multipart-0.0.7-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python310-python-multipart-0.0.7-1.1"},"product_reference":"python310-python-multipart-0.0.7-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python311-fastapi-0.109.1-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python311-fastapi-0.109.1-1.1"},"product_reference":"python311-fastapi-0.109.1-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python311-python-multipart-0.0.7-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python311-python-multipart-0.0.7-1.1"},"product_reference":"python311-python-multipart-0.0.7-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python312-fastapi-0.109.1-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python312-fastapi-0.109.1-1.1"},"product_reference":"python312-fastapi-0.109.1-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python312-python-multipart-0.0.7-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python312-python-multipart-0.0.7-1.1"},"product_reference":"python312-python-multipart-0.0.7-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python39-fastapi-0.109.1-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python39-fastapi-0.109.1-1.1"},"product_reference":"python39-fastapi-0.109.1-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python39-python-multipart-0.0.7-1.1 as component of openSUSE Tumbleweed","product_id":"openSUSE Tumbleweed:python39-python-multipart-0.0.7-1.1"},"product_reference":"python39-python-multipart-0.0.7-1.1","relates_to_product_reference":"openSUSE Tumbleweed"},{"category":"default_component_of","full_product_name":{"name":"python311-python-multipart as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:python311-python-multipart"},"product_reference":"python311-python-multipart","relates_to_product_reference":"openSUSE Leap 15.6"},{"category":"default_component_of","full_product_name":{"name":"python-python-multipart as component of openSUSE Leap 15.6","product_id":"openSUSE Leap 15.6:python-python-multipart"},"product_reference":"python-python-multipart","relates_to_product_reference":"openSUSE Leap 15.6"}]},"vulnerabilities":[{"cve":"CVE-2024-24762","ids":[{"system_name":"SUSE CVE Page","text":"https://www.suse.com/security/cve/CVE-2024-24762"}],"notes":[{"category":"general","text":"`python-multipart` is a streaming multipart parser for Python. When using form data, `python-multipart` uses a Regular Expression to parse the HTTP `Content-Type` header, including options. An attacker could send a custom-made `Content-Type` option that is very difficult for the RegEx to process, consuming CPU resources and stalling indefinitely (minutes or more) while holding the main event loop. This means that process can't handle any more requests, leading to regular expression denial of service. This vulnerability has been patched in version 0.0.7.","title":"CVE description"}],"product_status":{"known_not_affected":["openSUSE Leap 15.6:python-python-multipart","openSUSE Leap 15.6:python311-python-multipart"],"recommended":["SUSE Linux Enterprise Server 16.0:python313-fastapi-0.115.8-160000.2.2","SUSE Linux Enterprise Server 16.0:python313-python-multipart-0.0.20-160000.2.2","openSUSE Tumbleweed:python310-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python310-python-multipart-0.0.7-1.1","openSUSE Tumbleweed:python311-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python311-python-multipart-0.0.7-1.1","openSUSE Tumbleweed:python312-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python312-python-multipart-0.0.7-1.1","openSUSE Tumbleweed:python39-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python39-python-multipart-0.0.7-1.1"]},"references":[{"category":"external","summary":"CVE-2024-24762","url":"https://www.suse.com/security/cve/CVE-2024-24762"},{"category":"external","summary":"SUSE Security Ratings","url":"https://www.suse.com/support/security/rating/"},{"category":"external","summary":"SUSE Bug 1219603 for CVE-2024-24762","url":"https://bugzilla.suse.com/1219603"}],"remediations":[{"category":"vendor_fix","details":"To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n","product_ids":["SUSE Linux Enterprise Server 16.0:python313-fastapi-0.115.8-160000.2.2","SUSE Linux Enterprise Server 16.0:python313-python-multipart-0.0.20-160000.2.2","openSUSE Tumbleweed:python310-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python310-python-multipart-0.0.7-1.1","openSUSE Tumbleweed:python311-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python311-python-multipart-0.0.7-1.1","openSUSE Tumbleweed:python312-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python312-python-multipart-0.0.7-1.1","openSUSE Tumbleweed:python39-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python39-python-multipart-0.0.7-1.1"]}],"scores":[{"cvss_v3":{"baseScore":7.5,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"products":["SUSE Linux Enterprise Server 16.0:python313-fastapi-0.115.8-160000.2.2","SUSE Linux Enterprise Server 16.0:python313-python-multipart-0.0.20-160000.2.2","openSUSE Tumbleweed:python310-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python310-python-multipart-0.0.7-1.1","openSUSE Tumbleweed:python311-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python311-python-multipart-0.0.7-1.1","openSUSE Tumbleweed:python312-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python312-python-multipart-0.0.7-1.1","openSUSE Tumbleweed:python39-fastapi-0.109.1-1.1","openSUSE Tumbleweed:python39-python-multipart-0.0.7-1.1"]}],"threats":[{"category":"impact","date":"2024-02-05T16:00:15Z","details":"important"}],"title":"CVE-2024-24762"}]}