UBUNTU-CVE-2026-104874

Source
https://ubuntu.com/security/CVE-2026-104874
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-104874.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-104874
Upstream
Published
2026-10-05T00:00:00Z
Modified
2026-10-05T13:04:12Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1.

References

Affected packages

Ubuntu:18.04:LTS / python-multidict

Package

Name
python-multidict
Purl
pkg:deb/ubuntu/python-multidict?arch=source&distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.1.3-1build1
3.2.0-1
3.3.2-1
4.*
4.1.0-1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "python3-multidict",
            "binary_version":  "4.1.0-1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-104874.json"

Ubuntu:20.04:LTS / python-multidict

Package

Name
python-multidict
Purl
pkg:deb/ubuntu/python-multidict?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.5.2-1
4.6.1-1
4.7.3-1
4.7.3-1build1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "python3-multidict",
            "binary_version":  "4.7.3-1build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-104874.json"

Ubuntu:22.04:LTS / python-multidict

Package

Name
python-multidict
Purl
pkg:deb/ubuntu/python-multidict?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

5.*
5.1.0-1
5.1.0-1build1
5.1.0-1build2

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "python3-multidict",
            "binary_version":  "5.1.0-1build2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-104874.json"

Ubuntu:24.04:LTS / python-multidict

Package

Name
python-multidict
Purl
pkg:deb/ubuntu/python-multidict?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.0.4-1build1
6.0.4-1.1
6.0.4-1.1build1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "python3-multidict",
            "binary_version":  "6.0.4-1.1build1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-104874.json"

Ubuntu:26.04:LTS / python-multidict

Package

Name
python-multidict
Purl
pkg:deb/ubuntu/python-multidict?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

6.*
6.4.3-1
6.4.3-1build1
6.4.3-1build2

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "python3-multidict",
            "binary_version":  "6.4.3-1build2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-104874.json"