StackRadar

CVE-2026-104874

Medium

Advisory

Published 5 Oct 2026In the index since 6 Oct 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.003
20th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
119
of 18,026 indexed, latest versions
Container images
113
deployed by those charts
Fix available
1 of 2
affected packages

Multidict: Reference leak in CIMultiDict/MultiDict items-view union and subtraction

Carried by container images the latest versions of 119 of 18,026 indexed charts deploy, on 113 images.

Affected packageAffected versionsFixed inImages
multidictpypi6.7.0, 6.7.1, 6.8.0, 6.9.06.9.1112
python-multidictdeb6.0.4-1.1build1no fix listed1
OSV records
GHSA-54p9-h82j-f925UBUNTU-CVE-2026-104874

Charts affected

119 by stars
ChartLatestAffected imagesRadar Score
prowlerprowler0.1.11 of 1See more

prowler prowler 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
toniblyx/prowler:stablecf1ee9fc5b67
multidict@6.7.1
6.9.1

Open the chart page →

1,790
rawfile-localpvrawfile0.15.31 of 6See more

rawfile-localpv rawfile 0.15.3

1 of the 6 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
openebs/rawfile-localpv:v0.15.396fd7987ea79
multidict@6.7.1
6.9.1

Open the chart page →

3,782
checkmkrtomik-helm-chartsVerified publisher0.1.01 of 1See more

checkmk rtomik-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
checkmk/check-mk-community:2.5.0p6c11b422210c4
multidict@6.7.1
6.9.1

Open the chart page →

9,198
tandoorrtomik-helm-chartsVerified publisher0.0.11 of 1See more

tandoor rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
vabene1111/recipes:2.3.50f8d061895e9
multidict@6.7.0
6.9.1

Open the chart page →

4,891
runwhen-localrunwhen-contribVerified publisher0.7.01 of 3See more

runwhen-local runwhen-contrib 0.7.0

1 of the 3 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
ghcr.io/runwhen-contrib/runwhen-local:0.12.32c1ec86675d4
multidict@6.7.1
6.9.1

Open the chart page →

4,111
safe-config-servicesafe-global0.1.01 of 3See more

safe-config-service safe-global 0.1.0

1 of the 3 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
multidict@6.7.1
6.9.1

Open the chart page →

1,953
safe-stacksafe-global0.1.02 of 9See more

safe-stack safe-global 0.1.0

2 of the 9 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
safeglobal/safe-config-service:latest09a5e495c219
multidict@6.7.1
6.9.1
safeglobal/safe-transaction-service:latest7b576c73f865
multidict@6.7.1
6.9.1

Open the chart page →

20,820
safe-transaction-servicesafe-global0.1.01 of 6See more

safe-transaction-service safe-global 0.1.0

1 of the 6 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
safeglobal/safe-transaction-service:latest7b576c73f865
multidict@6.7.1
6.9.1

Open the chart page →

17,329
seafileschmitzis13.0.131 of 4See more

seafile schmitzis 13.0.13

1 of the 4 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
schmitzis/monorepo:seafile-13.0-latestf7e51ba2fb07
multidict@6.8.0
6.9.1

Open the chart page →

43,234
search-proxysearch-proxy2026.40.01 of 1See more

search-proxy search-proxy 2026.40.0

1 of the 1 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
ghcr.io/unique-ag/ai/search-proxy:2026.40.02bd74586650d
multidict@6.7.1
6.9.1

Open the chart page →

1,766
showroom-docs-mcpshowroom-docs-mcpVerified publisher2.1.01 of 4See more

showroom-docs-mcp showroom-docs-mcp 2.1.0

1 of the 4 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
litellm/litellm-non_root:v1.82.3-stable09b217802ded
multidict@6.7.1
6.9.1

Open the chart page →

6,095
home-assistantsmall-hack2.1.01 of 1See more

home-assistant small-hack 2.1.0

1 of the 1 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
ghcr.io/home-assistant/home-assistant:2026.3.10e091dfce306
multidict@6.7.1
6.9.1

Open the chart page →

4,850
srebotsrebot0.14.01 of 2See more

srebot srebot 0.14.0

1 of the 2 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
ghcr.io/shadrus/srebot:0.14.09b4415e937b2
multidict@6.7.1
6.9.1

Open the chart page →

1,832
servicexssl-hep1.8.61 of 16See more

servicex ssl-hep 1.8.6

1 of the 16 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
sslhep/servicex-did-finder:v1.8.6e15e68307d33
multidict@6.7.1
6.9.1

Open the chart page →

61,380
surogate-hubsurogate-hubVerified publisher2.1.51 of 1See more

surogate-hub surogate-hub 2.1.5

1 of the 1 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
ghcr.io/invergent-ai/surogate-hub:latest6d4106724d56
multidict@6.7.1
6.9.1

Open the chart page →

4,102
svc-lb-muxsvc-lb-mux0.1.31 of 1See more

svc-lb-mux svc-lb-mux 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
ghcr.io/nowakeai/svc-lb-mux:0.1.37d8fb8e996b6
multidict@6.7.1
6.9.1

Open the chart page →

1,742
wasabi-s3-operatorwasabi-s3-operatorVerified publisher0.2.71 of 1See more

wasabi-s3-operator wasabi-s3-operator 0.2.7

1 of the 1 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
multidict@6.7.1
6.9.1

Open the chart page →

743
dingtalk-botxxl-job-adminVerified publisher0.1.31 of 2See more

dingtalk-bot xxl-job-admin 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
multidict@6.7.0
6.9.1

Open the chart page →

3,752
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-104874.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
multidict@6.8.0
6.9.1

Open the chart page →

5,028

Container images carrying it

113 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/paperless-ngx/paperless-ngx:3.1.3aa810a36942c
multidict@6.7.1
6.9.1
4
ghcr.io/flyteorg/flyte-connectors:py3.12-v2.3.6896fc7b18b1b
multidict@6.7.1
6.9.1
3
ghcr.io/paperless-ngx/paperless-ngx:3.2.15fa76604a81d
multidict@6.7.1
6.9.1
3
gisaia/airs:0.19.08b88432c8d1f
multidict@6.8.0
6.9.1
2
gisaia/aproc-service:0.19.086e69fdc9d9e
multidict@6.8.0
6.9.1
2
gisaia/fam:0.19.0ff9526c6276c
multidict@6.8.0
6.9.1
2
ilum/api:6.7.3624fd09528c8
multidict@6.7.1
6.9.1
2
langflowai/langflow:latest4304bd9e67db
multidict@6.7.1
6.9.1
2
nacos/nacos-server:latest1c191c30c8cd
multidict@6.7.1
6.9.1
2
nousresearch/hermes-agent:v2026.9.24fca358f12efd
multidict@6.7.1
6.9.1
2
polyaxon/polyaxon-agent:2.17.0da877a2647fc
multidict@6.8.0
6.9.1
2
polyaxon/polyaxon-cli:2.17.0297ed47ed63a
multidict@6.8.0
6.9.1
2
safeglobal/safe-config-service:latest09a5e495c219
multidict@6.7.1
6.9.1
2
safeglobal/safe-transaction-service:latest7b576c73f865
multidict@6.7.1
6.9.1
2
ghcr.io/goauthentik/server:2026.8.3ab9b4e8cc4ab
multidict@6.7.1
6.9.1
2
ghcr.io/xeor/karb:1.0.6:main647a3c938d31
multidict@6.7.1
6.9.1
2
acryldata/datahub-actions:v1.7.0.1c5fd70130157
multidict@6.7.1
6.9.1
1
agentarea/agentarea-api:latestf9033ebe2e00
multidict@6.7.1
6.9.1
1
agentarea/agentarea-worker:latestf4745afdace1
multidict@6.7.1
6.9.1
1
aibrix/metadata-service:v0.7.063fb81a64377
multidict@6.7.1
6.9.1
1
archivebox/archivebox:0.9.708c21bb233130
multidict@6.9.0
6.9.1
1
arunvelsriram/utils:latest655ad18fd8d6
python-multidict@6.0.4-1.1build1
no fix listed
1
berkeleyskypilot/skypilot-nightly:latest8da2f3cda472
multidict@6.7.0
6.9.1
1
burakince/mlflow:3.16.0ab4b566644b9
multidict@6.7.1
6.9.1
1
byjg/easy-haproxy:6.1.1230fdb7b00ae
multidict@6.7.1
6.9.1
1
checkmk/check-mk-community:2.5.0p6c11b422210c4
multidict@6.7.1
6.9.1
1
chiefonboarding/chiefonboarding:v2.5.0d0964135ea82
multidict@6.8.0
6.9.1
1
dagster/dagster-cloud-agent:1.13.257c13aa1c9a7a
multidict@6.7.1
6.9.1
1
datagrok/grok_spawner:latest8c2d48c1545c
multidict@6.7.1
6.9.1
1
dellnoantechnp/dingtalk-bot:v1.0.1034000bbcad5
multidict@6.7.0
6.9.1
1
dgtlmoon/sockpuppetbrowser:latest1d8f72d2ce20
multidict@6.8.0
6.9.1
1
esphome/esphome:2026.7.44866347cb5b4
multidict@6.7.1
6.9.1
1
greenkube/greenkube:0.3.00c01932282a4
multidict@6.7.1
6.9.1
1
homeassistant/home-assistant:2026.75a531753cea9
multidict@6.7.1
6.9.1
1
intelowlproject/intelowl:v6.6.10b22e547ea6b
multidict@6.7.1
6.9.1
1
jertel/elastalert2:2.31.03cbf63f9b7dc
multidict@6.7.1
6.9.1
1
jupyterjsc/jupyterhub-outpost:2.3.1aea53b13f235
multidict@6.7.1
6.9.1
1
kenchrcum/ansible-playbook-operator:0.1.712fb213debf1
multidict@6.7.1
6.9.1
1
kenchrcum/hetzner-s3-operator:0.1.384dae7aeea5b
multidict@6.7.1
6.9.1
1
kenchrcum/wasabi-s3-operator:0.2.7ce657c622ce5
multidict@6.7.1
6.9.1
1
langflowai/langflow:1.12.334055a07d446
multidict@6.7.1
6.9.1
1
langgenius/dify-api:1.16.1dcefa5f7c47c
multidict@6.7.0
6.9.1
1
langgenius/dify-plugin-daemon:0.6.3-local3c694329357b
multidict@6.7.1
6.9.1
1
langgenius/dify-plugin-daemon:0.5.1-local8269050f192e
multidict@6.7.0
6.9.1
1
litellm/litellm-non_root:v1.82.3-stable09b217802ded
multidict@6.7.1
6.9.1
1
loeken/home-assistant:2026.5.14ce6abc553b3
multidict@6.7.1
6.9.1
1
lumutools/kubernetes-feeder:lateste35ffa90b129
multidict@6.7.1
6.9.1
1
maponyacharles/sceptreai:mlflow-0.1.1242d418654ebd
multidict@6.7.1
6.9.1
1
maponyacharles/sceptreai:api-0.1.127b37b092130a
multidict@6.7.1
6.9.1
1
mathesar/mathesar:0.12.0091757cb01fe
multidict@6.7.1
6.9.1
1

syft 1.42.1 · advisories as of 6 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.