Threat Advisory

Multidict Reference Leak Drives Unbounded Memory Growth

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Medium
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-104874 with a CVSS score of 5.3 is a reference leak in the items-view union and subtraction operators of aio-libs/multidict versions prior to 6.9.0, allowing remote clients to drive unbounded, unreclaimable memory growth by having each operand element leak one key-identity object and one value object. The reflected-union path (`operand | d.items`, `multidict_itemsview_or2_impl`) and the subtraction path (`d.items - operand`, `multidict_itemsview_sub1_impl`) parse each element into new strong references but release only the tuple wrapper, never the identity and value. Servers in the aio-libs stack build these views over attacker-supplied HTTP headers and query strings, so the operand size is under remote control. Forced garbage collection does not recover the leaked objects, so resident memory rises monotonically until the process is killed affecting multidict versions >= 6.7.0, <= 6.9.0.

RECOMMENDATION:

We recommend you to update aio-libs/multidict to version 6.9.1.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-104874 with a CVSS score of 5.3 is a reference leak in the items-view union and subtraction operators of aio-libs/multidict versions prior to 6.9.0, allowing remote clients to drive unbounded, unreclaimable memory growth by having each operand element leak one key-identity object and one value object. The reflected-union path (`operand | d.items`, `multidict_itemsview_or2_impl`) and the subtraction path (`d.items - operand`, `multidict_itemsview_sub1_impl`) parse each element into new strong references but release only the tuple wrapper, never the identity and value. Servers in the aio-libs stack build these views over attacker-supplied HTTP headers and query strings, so the operand size is under remote control. Forced garbage collection does not recover the leaked objects, so resident memory rises monotonically until the process is killed affecting multidict versions >= 6.7.0, <= 6.9.0.

RECOMMENDATION:

We recommend you to update aio-libs/multidict to version 6.9.1.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu