multidict: multidict: Denial of Service via memory leak in items-view operations

cve CVE-2026-104874 2 sources, 2 claims · Watch

Red Hat writes:
multidict: multidict: Denial of Service via memory leak in items-view operations the claim

What it is to other things

In words only, so not counted until a person confirms one:

affectsaio_libs/multidict
NVD says “aio-libs · multidict”
made_byaio_libs
NVD says “aio-libs”

What each source says

PropertySourceSaidMeans here
Cvss
cvss
NVD5.3
receipt
Source
NVD
Its words
5.3
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "multidict",
            "vendor": "aio-libs",
            "versions": [
              {
                "status": "affected",
                "version": ">= 6.7.0, < 6.9.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1."
      }
    ],
    "id": "CVE-2026-104874",
    "lastModified": "2026-10-02T21:16:54.993",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T21:16:54.993",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/commit/350b4a07bf8ff851b6d7544e81b1c748bdc74c40"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/releases/tag/v6.9.1"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/security/advisories/GHSA-54p9-h82j-f925"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Cvss
cvss
Red Hat5.3
receipt
Source
Red Hat
Its words
5.3
Read by
field:cvss3_score
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-104874",
  "CWE": "CWE-911",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2545386",
  "bugzilla_description": "multidict: multidict: Denial of Service via memory leak in items-view operations",
  "cvss3_score": "5.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-02T20:21:50Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-104874.json",
  "severity": "moderate"
}
—
Cwe
cwe
Red HatCWE-911
receipt
Source
Red Hat
Its words
CWE-911
Read by
field:CWE
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-104874",
  "CWE": "CWE-911",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2545386",
  "bugzilla_description": "multidict: multidict: Denial of Service via memory leak in items-view operations",
  "cvss3_score": "5.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-02T20:21:50Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-104874.json",
  "severity": "moderate"
}
—
Product
product
NVDmultidict
receipt
Source
NVD
Its words
multidict
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "multidict",
            "vendor": "aio-libs",
            "versions": [
              {
                "status": "affected",
                "version": ">= 6.7.0, < 6.9.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1."
      }
    ],
    "id": "CVE-2026-104874",
    "lastModified": "2026-10-02T21:16:54.993",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T21:16:54.993",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/commit/350b4a07bf8ff851b6d7544e81b1c748bdc74c40"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/releases/tag/v6.9.1"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/security/advisories/GHSA-54p9-h82j-f925"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Severity
severity
Red Hatmoderate
A flaw that is harder to exploit, or whose impact is limited.
receipt
Source
Red Hat
Its words
moderate
Read by
field:severity
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-104874",
  "CWE": "CWE-911",
  "advisories": [],
  "affected_packages": [],
  "bugzilla": "2545386",
  "bugzilla_description": "multidict: multidict: Denial of Service via memory leak in items-view operations",
  "cvss3_score": "5.3",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-10-02T20:21:50Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-104874.json",
  "severity": "moderate"
}
medium
Status
status
NVDReceived
receipt
Source
NVD
Its words
Received
Read by
field:cve.vulnStatus
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "multidict",
            "vendor": "aio-libs",
            "versions": [
              {
                "status": "affected",
                "version": ">= 6.7.0, < 6.9.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1."
      }
    ],
    "id": "CVE-2026-104874",
    "lastModified": "2026-10-02T21:16:54.993",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T21:16:54.993",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/commit/350b4a07bf8ff851b6d7544e81b1c748bdc74c40"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/releases/tag/v6.9.1"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/security/advisories/GHSA-54p9-h82j-f925"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—
Vendor
vendor
NVDaio-libs
receipt
Source
NVD
Its words
aio-libs
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-03 00:06 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "multidict",
            "vendor": "aio-libs",
            "versions": [
              {
                "status": "affected",
                "version": ">= 6.7.0, < 6.9.1"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1."
      }
    ],
    "id": "CVE-2026-104874",
    "lastModified": "2026-10-02T21:16:54.993",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 1.4,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ]
    },
    "published": "2026-10-02T21:16:54.993",
    "references": [
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/commit/350b4a07bf8ff851b6d7544e81b1c748bdc74c40"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/releases/tag/v6.9.1"
      },
      {
        "source": "security-advisories@github.com",
        "url": "https://github.com/aio-libs/multidict/security/advisories/GHSA-54p9-h82j-f925"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Received",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-401"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Primary"
      }
    ]
  }
}
—

vulnerability

multidict: multidict: Denial of Service via memory leak in items-view operations
zetlyn/cve-redhat · 2026-10-02
cvss 5.3 cwe CWE-911 severity moderate source
Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1.
zetlyn/cve-nvd · 2026-10-02
cvss 5.3 product multidict status Received vendor aio-libs source