CVE-2026-104874
Received Received - Intake

Memory Leak in Multidict C Extension

Vulnerability report for CVE-2026-104874, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-401 The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Multidict library versions 6.7.0 to 6.9.1. It involves a reference leak in the C extension's items-view operations, specifically the union (|) and subtraction (-) operations. When these operations are performed on attacker-controlled sequences, they fail to release new key-identity and value references, causing memory leaks. This can lead to unbounded process memory growth and denial of service.

Detection Guidance

This vulnerability affects applications using Multidict versions 6.7.0 to 6.9.1. To detect it, check the installed version of Multidict with pip show multidict. If the version is within the affected range, the application may be vulnerable. No specific commands are provided for detection beyond version checks.

Impact Analysis

If you use Multidict in versions 6.7.0 to 6.9.1, an attacker could exploit this flaw to cause your application to consume excessive memory. This may result in slow performance, crashes, or complete denial of service, disrupting normal operations.

Mitigation Strategies

Upgrade Multidict to version 6.9.1 or later immediately. Use pip install --upgrade multidict to apply the fix. If upgrading is not possible, avoid using the affected operations (items-view union and subtraction) in your code.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104874. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart