<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:22:16.135428+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-advai-cli-cve-2026-104874</id>
    <title>BREW-advai-cli-CVE-2026-104874 — Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction</title>
    <updated>2026-10-06T22:22:16.504467+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: advai-cli</p>
<p>## Description</p>
<p>A reference leak in the items-view union and subtraction operators of aio-libs/multidict 6.7.0 through 6.9.0 (C extension) lets a remote client drive unbounded, unreclaimable memory growth by having each operand element leak one key-identity object and one value object. The reflected-union path (`operand | d.items()`, `multidict_itemsview_or2_impl`) and the subtraction path (`d.items() - operand`, `multidict_itemsview_sub1_impl`) parse each element into new strong references but release only the tuple wrapper, never the identity and value. Servers in the aio-libs stack build these views over attacker-supplied HTTP headers and query strings, so the operand size is under remote control. Forced garbage collection does not recover the leaked objects, so resident memory rises monotonically until the process is killed.</p>
<p>---</p>
<p>## Root Cause</p>
<p>`_multidict_itemsview_parse_item()` returns **new** references: a fresh identity via `md_calc_identity()` and a fresh value via `Py_NewRef()`. The `or2_impl` first parse loop requests both but clears only `arg`:</p>
<p>```c
// views.h:565 — or2_impl first parse loop
while ((st = PyIter_NextItem(iter, &amp;arg)) &gt; 0) {
    int tmp = _multidict_itemsview_parse_item(
        self, arg, &amp;identity, NULL, &amp;value);   // identity + value: new refs
    if (tmp &lt; 0) goto fail;
    else if (tmp &gt; 0) {
        if (_set_add(tmp_set, identity, value) &lt; 0) goto fail;
    }
    Py_CLEAR(arg);                             // :575 clears arg ONLY
}
```</p>
<p>`_se…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-advai-cli-cve-2026-104874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-382456</id>
    <title>EUVD-2026-382456</title>
    <updated>2026-10-06T22:22:16.504629+00:00</updated>
    <content>EUVD-2026-382456</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-382456"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-104874</id>
    <title>fkie_cve-2026-104874</title>
    <updated>2026-10-06T22:22:16.504646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-104874"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-54p9-h82j-f925</id>
    <title>GHSA-54p9-h82j-f925 — Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction</title>
    <updated>2026-10-06T22:22:16.504676+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: multidict</p>
<p>## Description</p>
<p>A reference leak in the items-view union and subtraction operators of aio-libs/multidict 6.7.0 through 6.9.0 (C extension) lets a remote client drive unbounded, unreclaimable memory growth by having each operand element leak one key-identity object and one value object. The reflected-union path (`operand | d.items()`, `multidict_itemsview_or2_impl`) and the subtraction path (`d.items() - operand`, `multidict_itemsview_sub1_impl`) parse each element into new strong references but release only the tuple wrapper, never the identity and value. Servers in the aio-libs stack build these views over attacker-supplied HTTP headers and query strings, so the operand size is under remote control. Forced garbage collection does not recover the leaked objects, so resident memory rises monotonically until the process is killed.</p>
<p>---</p>
<p>## Root Cause</p>
<p>`_multidict_itemsview_parse_item()` returns **new** references: a fresh identity via `md_calc_identity()` and a fresh value via `Py_NewRef()`. The `or2_impl` first parse loop requests both but clears only `arg`:</p>
<p>```c
// views.h:565 — or2_impl first parse loop
while ((st = PyIter_NextItem(iter, &amp;arg)) &gt; 0) {
    int tmp = _multidict_itemsview_parse_item(
        self, arg, &amp;identity, NULL, &amp;value);   // identity + value: new refs
    if (tmp &lt; 0) goto fail;
    else if (tmp &gt; 0) {
        if (_set_add(tmp_set, identity, value) &lt; 0) goto fail;
    }
    Py_CLEAR(arg);                             // :575 clears arg ONLY
}
```</p>
<p>`_se…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-54p9-h82j-f925"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-104874</id>
    <title>UBUNTU-CVE-2026-104874</title>
    <updated>2026-10-06T22:22:16.504746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: python-multidict, Ubuntu:20.04:LTS: python-multidict, Ubuntu:22.04:LTS: python-multidict, Ubuntu:24.04:LTS: python-multidict, Ubuntu:26.04:LTS: python-multidict</p>
<p>Multidict is an implementation of a multidict data structure. From 6.7.0 until 6.9.1, the C extension's items-view reflected union operation, operand | d.items(), in multidict_itemsview_or2_impl and subtraction operation, d.items() - operand, in multidict_itemsview_sub1_impl fail to release new key-identity and value references returned for each operand element. Applications that perform these operations over attacker-influenced sequences can leak two strong references per element, and garbage collection cannot reclaim them, so repeated operations can cause unbounded process memory growth and denial of service. Forward union, intersection, non-tuple operand elements, and pure-Python builds are not affected by this reference leak. This issue is fixed in version 6.9.1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-104874"/>
  </entry>
</feed>
