CVE-2026-24486

Red Hat Security Advisory: satellite/iop-vulnerability-engine-rhel9 container image available as a Technology Preview

Description

A flaw was found in Python-Multipart, a tool for parsing multipart form data in Python applications. This vulnerability, known as path traversal, allows a remote attacker to write uploaded files to any location on the server's file system. This exploitation occurs when specific non-default configuration options, `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`, are enabled, and a malicious filename is provided during a file upload. The primary consequence is unauthorized file creation or modification, which could lead to system compromise.

Metrics

Severity
high
no public PoC known
8.6
Source: cna-v3
81.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
2.2 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-08-06 20:30 UTC
CWE-22

Weakness classes (CWE)

  • CWE-22Base

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

    The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-07-24 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:44696
    • Affected: Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat Ansible Automation Platform 2.6 (+62)Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat Ansible Automation Platform 2.6 (+62)
  2. CVE Modified2026-07-21 12:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:42644
    • Affected: Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat Ansible Automation Platform 2.6 (+62)Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat Ansible Automation Platform 2.6 (+62)

Affected operating systems

  • linux

    redhat / enterprise_linux_ai3.0

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • encode

    starlette0.8.3 – 1.0.1

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • IBM

    QRadar SIEM<7.5.0 UP15 IF06

  • pypi

    urllib31.0

  • pypi

    urllib31.0.1

  • pypi

    urllib31.0.2

  • pypi

    urllib31.1

  • pypi

    urllib31.10

  • pypi

    urllib31.10.1

  • pypi

    urllib31.10.2

  • pypi

    urllib31.10.3

  • pypi

    urllib31.10.4

  • pypi

    urllib31.11

  • pypi

    urllib31.12

  • pypi

    urllib31.13

  • pypi

    urllib31.13.1

  • pypi

    urllib31.14

  • pypi

    urllib31.15

  • pypi

    urllib31.15.1

  • pypi

    urllib31.16

  • pypi

    urllib31.17

  • pypi

    urllib31.18

  • pypi

    urllib31.18.1

  • pypi

    urllib31.19

References & sources

Linked CVEs

IDCVE-2026-24486