CVE-2026-104874 Multidict 内存泄漏漏洞
影响攻击者可触发进程内存无限增长,导致拒绝服务
Multidict 是一个 multidict 数据结构的实现。其 C 扩展在 items 视图的反射并集(operand | d.items())与减法(d.items() - operand)操作中,未能释放为每个操作数元素返回的新键标识和值引用。攻击者若能影响操作序列,可导致内存持续增长并最终造成拒绝服务。
影响范围
Multidict 6.7.0 至 6.9.1 之前的版本受影响;6.9.1 已修复。纯 Python 构建不受影响。
漏洞详情
漏洞类型为内存泄漏(引用计数未释放)。成因是 C 扩展中 multidict_itemsview_or2_impl 与 multidict_itemsview_sub1_impl 两个函数在处理每个操作数元素时,未释放新创建的键标识和值引用,导致每个元素泄漏两个强引用,垃圾回收无法回收。利用方式是让应用对攻击者可控的序列反复执行上述反射并集或减法操作,从而造成进程内存无界增长。正向并集、交集、非元组操作数元素及纯 Python 构建不受影响。
利用条件与风险
利用前提是应用对攻击者可控的序列执行 d.items() 的反射并集或减法操作;实战中可导致内存耗尽型拒绝服务,CVSS 5.3 为中危。
修复建议
升级至 Multidict 6.9.1 或更高版本。临时缓解措施:避免对不可信输入执行 items 视图的反射并集与减法操作,或改用纯 Python 构建。暂无其他公开信息。
Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension’s items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() – operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1.