CVE-2026-24486
Red Hat Security Advisory: satellite/iop-vulnerability-engine-rhel9 container image available as a Technology Preview
Description
A flaw was found in Python-Multipart, a tool for parsing multipart form data in Python applications. This vulnerability, known as path traversal, allows a remote attacker to write uploaded files to any location on the server's file system. This exploitation occurs when specific non-default configuration options, `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=True`, are enabled, and a malicious filename is provided during a file upload. The primary consequence is unauthorized file creation or modification, which could lead to system compromise.
Metrics
Weakness classes (CWE)
CWE-22Base
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-07-24 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:44696
- Affected: Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat Ansible Automation Platform 2.6 (+62) → Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat Ansible Automation Platform 2.6 (+62)
- CVE Modified2026-07-21 12:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:42644
- Affected: Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat Ansible Automation Platform 2.6 (+62) → Red Hat AI Inference Server 3.2, Red Hat AI Inference Server 3.2, Red Hat Ansible Automation Platform 2.6 (+62)
Affected operating systems
linux
redhat / enterprise_linux_ai3.0
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
encode
starlette0.8.3 – 1.0.1
IBM
Concert< 3.0.0
fixed in 3.0.0
IBM
QRadar SIEM<7.5.0 UP15 IF06
pypi
urllib31.0
pypi
urllib31.0.1
pypi
urllib31.0.2
pypi
urllib31.1
pypi
urllib31.10
pypi
urllib31.10.1
pypi
urllib31.10.2
pypi
urllib31.10.3
pypi
urllib31.10.4
pypi
urllib31.11
pypi
urllib31.12
pypi
urllib31.13
pypi
urllib31.13.1
pypi
urllib31.14
pypi
urllib31.15
pypi
urllib31.15.1
pypi
urllib31.16
pypi
urllib31.17
pypi
urllib31.18
pypi
urllib31.18.1
pypi
urllib31.19
References & sources
- https://github.com/urllib3/urllib3/security/advisories/GHSA-38jv-5279-wg99web
- https://nvd.nist.gov/vuln/detail/CVE-2026-21441advisory
- https://github.com/urllib3/urllib3/commit/8864ac407bba8607950025e0979c4c69bc7abc7bweb
- https://github.com/urllib3/urllib3package
- https://lists.debian.org/debian-lts-announce/2026/01/msg00017.htmlweb
- https://access.redhat.com/security/cve/CVE-2026-21441vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2427726issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-21441.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:2911vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:28043vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:1485vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:2765vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:2764vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:2760vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:1240vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:1224vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:1226vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:1803vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:1792vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:1791vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2026-48710Actively exploited
A flaw was found in Starlette, a lightweight ASGI (Asynchronous Server Gateway Interface) framework.
criticalCVSSv3 6.5 - CVE-2026-44431
A flaw was found in urllib3, an HTTP client library for Python.
high - CVE-2026-42561
A flaw was found in python-multipart.
highCVSSv3 7.5 - CVE-2026-21441
urllib3 is an HTTP client library for Python.
highCVSSv3 7.5 - CVE-2025-66471
A decompression handling flaw has been discovered in urllib3.
high