Memory Leak Vulnerability in Multidict Product by Aio-libs
CVE-2026-104874
5.3MEDIUM
What is CVE-2026-104874?
The Multidict product from Aio-libs versions 6.7.0 to 6.9.1 contains a vulnerability where the C extension's items-view mishandles key and value references during specific operations. This flaw allows attacker-influenced sequences to leak strong references, resulting in unbounded memory growth and potential denial of service as garbage collection fails to reclaim the leaked references. This issue has been addressed in version 6.9.1.
Affected Version(s)
multidict >= 6.7.0, < 6.9.1
