CVE-2026-104874: Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction

Published Oct 2, 2026
·
Updated

Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidictitemsviewor2impl and subtraction operation, d.items() - operand, in multidictitemsviewsub1impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1.

Affected Software

1 affected component
pypi/multidict>=6.7.0<6.9.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade multidict to a version that resolves this vulnerability.

    Fixed in 6.9.1

Event History

Oct 2, 2026
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to the memory leak?

Deployments using Multidict versions from 6.7.0 through 6.9.1 with the C extension are affected when they perform the vulnerable items-view operations. Pure-Python builds are not affected.

2

What attacker influence is needed to trigger denial of service?

An attacker needs to influence sequences processed by the reflected union operation, operand | d.items(), or the subtraction operation, d.items(). Repeating these operations can leak two strong references per operand element and cause unbounded process memory growth.

3

Which similar operations are not affected?

Forward union, intersection, and operations involving non-tuple operand elements are not affected by this reference leak.

4

What is the available remediation?

Update Multidict to version 6.9.1, which fixes the issue. If updating is not immediately possible, avoid applying reflected union or subtraction items-view operations to attacker-influenced sequences.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203