litellm - 💡(How to fix) Fix [Bug]: Update python-multipart pin to >= 0.0.26 (CVE-2026-40347)

Official PRs (…)
ON THIS PAGE

Recommended Tools

×6

Utilities matched from this issue’s tags and category — try them while you read without losing context.

GitHub issue graph ai analysis

Paste a GitHub issue URL. We fetch that issue, discover linked issues from bodies/comments/timeline, collect linked pull requests, and produce a structured English report.

The report is written in English Markdown for sharing and archival.

Helpful · Quick feedback

Loading…

The proxy dependency python-multipart is pinned to 0.0.20 in pyproject.toml. This version is affected by CVE-2026-40347 (CVSS 5.3, DoS via crafted multipart preamble/epilogue). The fix is available in 0.0.26+.

Root Cause

The proxy dependency python-multipart is pinned to 0.0.20 in pyproject.toml. This version is affected by CVE-2026-40347 (CVSS 5.3, DoS via crafted multipart preamble/epilogue). The fix is available in 0.0.26+.

Fix Action

Fix / Workaround

  1. Pull any official LiteLLM proxy image (e.g. ghcr.io/berriai/litellm:v1.83.10-stable.patch-nonroot)
  2. Run a container image scan. (fortify, trivy, prisma cloud, etc.)

Code Example

"python-multipart==0.0.20",

---

"python-multipart>=0.0.27",

---
RAW_BUFFERClick to expand / collapse

Check for existing issues

  • I have searched the existing issues and checked that my issue is not a duplicate.

What happened?

Summary

The proxy dependency python-multipart is pinned to 0.0.20 in pyproject.toml. This version is affected by CVE-2026-40347 (CVSS 5.3, DoS via crafted multipart preamble/epilogue). The fix is available in 0.0.26+.

Affected line

https://github.com/BerriAI/litellm/blob/litellm_internal_staging/pyproject.toml

"python-multipart==0.0.20",

Suggested fix

"python-multipart>=0.0.27",

References

Steps to Reproduce

  1. Pull any official LiteLLM proxy image (e.g. ghcr.io/berriai/litellm:v1.83.10-stable.patch-nonroot)
  2. Run a container image scan. (fortify, trivy, prisma cloud, etc.)

Relevant log output

What part of LiteLLM is this about?

Proxy

What LiteLLM version are you on ?

v1.83.10

Twitter / LinkedIn details

No response

Vote matrix · Quick signals

Works
Did the solution work? Tap to confirm.
Easy Fix
Was it a quick fix?
Time Saver
Did it save you time?
Blocking
Was it severely blocking?
Common Issue
Are others likely hitting this too?
Flaky / Intermittent
Is it intermittent?
Verified / Reproducible
Can you reproduce it reliably?
Loading…

Still need to ship something?

×6

Another batch ranked right after the header list — different links, same matching logic.

Back to top recommendations

TRENDING

litellm - 💡(How to fix) Fix [Bug]: Update python-multipart pin to >= 0.0.26 (CVE-2026-40347)