CWE-226: Sensitive Information in Resource Not Removed Before Reuse
The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.
35 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2019-25560 — Lyric Video Creator 2.1 Denial of Service via MP3 File
- CVE-2026-74791 — Scriban before 7.0.0 Authorization Bypass via Stale Include Cache
- CVE-2019-25645 — WinAVI iPod 3GP MP4 PSP Converter 4.4.2 Denial of Service
- CVE-2019-25617 — Ease Audio Converter 5.30 Denial of Service via Audio Cutter
- CVE-2019-25571 — MediaMonkey 4.1.23 Denial of Service via Malformed URL
- CVE-2019-25563 — PCHelpWareV2 1.0.0.5 Denial of Service via SC Creation
- CVE-2019-25553 — CEWE PHOTO IMPORTER 6.4.3 Denial of Service via Malformed Image
- CVE-2026-13585 — Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in
- CVE-2025-2522 — Lack of buffer clearing before reuse may result in incorrect system behavior.
- CVE-2025-11602 — Untargeted information leak in Bolt protocol handshake
- CVE-2026-47247 — libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation
- CVE-2026-5795 — In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.
- CVE-2025-48066 — wire-webapp has no database deletion on client logout
- CVE-2026-32960 — SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource no
- CVE-2019-25657 — AnyBurn 4.3 x86 Denial of Service via Image Conversion
- CVE-2024-32036 — SixLabors.ImageSharp vulnerable to data leakage
- CVE-2026-74250 — In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment
- CVE-2026-18023 — Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose
- CVE-2025-33196 — NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.
- CVE-2025-14858 — Semtech LR11xx Encrypted Firmware Disclosure
Recently published
- CVE-2026-18023 — Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose
- CVE-2026-74791 — Scriban before 7.0.0 Authorization Bypass via Stale Include Cache
- CVE-2026-74250 — In OpenStack Ironic before 38.0.1, the autodetect deploy interface may fail to run cleaning immediately after enrollment
- CVE-2026-47247 — libheif Vulnerable to Heap Information Disclosure via Grid Image Gap + Uninitialized Pixel Plane Allocation
- CVE-2026-13585 — Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in
- CVE-2026-48984 — pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heap
- CVE-2026-32960 — SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource no
- CVE-2026-5795 — In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.
- CVE-2025-14858 — Semtech LR11xx Encrypted Firmware Disclosure
- CVE-2019-25657 — AnyBurn 4.3 x86 Denial of Service via Image Conversion
- CVE-2019-25645 — WinAVI iPod 3GP MP4 PSP Converter 4.4.2 Denial of Service
- CVE-2019-25617 — Ease Audio Converter 5.30 Denial of Service via Audio Cutter
- CVE-2019-25571 — MediaMonkey 4.1.23 Denial of Service via Malformed URL
- CVE-2019-25563 — PCHelpWareV2 1.0.0.5 Denial of Service via SC Creation
- CVE-2019-25560 — Lyric Video Creator 2.1 Denial of Service via MP3 File
- CVE-2019-25553 — CEWE PHOTO IMPORTER 6.4.3 Denial of Service via Malformed Image
- CVE-2025-0647 — In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a
- CVE-2025-33200 — NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.
- CVE-2025-33198 — NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.
- CVE-2025-33196 — NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.
More specific weaknesses
- CWE-1239 — Improper Zeroization of Hardware Register
- CWE-1272 — Sensitive Information Uncleared Before Debug/Power State Transition
- CWE-1301 — Insufficient or Incomplete Data Removal within Hardware Component
- CWE-1342 — Information Exposure through Microarchitectural State after Transient Execution
- CWE-244 — Heap Inspection