CVE-2026-104874: Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction
Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidictitemsviewor2impl and subtraction operation, d.items() - operand, in multidictitemsviewsub1impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
multidictto a version that resolves this vulnerability.Fixed in 6.9.1
Event History
Frequently Asked Questions
Which deployments are exposed to the memory leak?
Deployments using Multidict versions from 6.7.0 through 6.9.1 with the C extension are affected when they perform the vulnerable items-view operations. Pure-Python builds are not affected.
What attacker influence is needed to trigger denial of service?
An attacker needs to influence sequences processed by the reflected union operation, operand | d.items(), or the subtraction operation, d.items(). Repeating these operations can leak two strong references per operand element and cause unbounded process memory growth.
Which similar operations are not affected?
Forward union, intersection, and operations involving non-tuple operand elements are not affected by this reference leak.
What is the available remediation?
Update Multidict to version 6.9.1, which fixes the issue. If updating is not immediately possible, avoid applying reflected union or subtraction items-view operations to attacker-influenced sequences.