The vendor explicitly identifies these products as affected by this CVE.
- lightspeed-core/lightspeed-stack-rhel9 as a component of Lightspeed Core
- lightspeed-core/rag-tool-rhel9 as a component of Lightspeed Core
- openshift-lightspeed/lightspeed-service-api-rhel9 as a component of OpenShift Lightspeed
- rhaiis/vllm-cpu-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-neuron-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-spyre-rhel9 as a component of Red Hat AI Inference Server
- rhaiis/vllm-tpu-rhel9 as a component of Red Hat AI Inference Server
- rhelai3/bootc-aws-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-azure-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-azure-rocm-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- rhelai3/bootc-gcp-cuda-rhel9 as a component of Red Hat Enterprise Linux AI (RHEL AI) 3
- Summary
- A flaw was found in multipart. The parse_options_header function in multipart.py uses a regular expression with an ambiguous alternation, causing an exponential backtracking (ReDoS) when parsing a specially crafted HTTP or multipart segment headers. A web application parsing request headers or multipart/form-data streams can block request handling threads for multiple seconds per request, eventually resulting in a denial of service.
- Remediation
- For more information visit https://access.redhat.com/errata/RHSA-2026:6761
