Memory Leak Vulnerability in Multidict Product by Aio-libs
CVE-2026-104874

5.3MEDIUM

Key Information:

Vendor

Aio-libs

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104874?

The Multidict product from Aio-libs versions 6.7.0 to 6.9.1 contains a vulnerability where the C extension's items-view mishandles key and value references during specific operations. This flaw allows attacker-influenced sequences to leak strong references, resulting in unbounded memory growth and potential denial of service as garbage collection fails to reclaim the leaked references. This issue has been addressed in version 6.9.1.

Affected Version(s)

multidict >= 6.7.0, < 6.9.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.