CWE-401: Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
301 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-3650 — Grassroots DICOM Missing release of memory after effective lifetime
- CVE-2025-61974 — BIG-IP SSL/TLS vulnerability
- CVE-2025-30658 — Junos OS: SRX Series: On devices with Anti-Virus enabled, malicious server responses will cause memory to leak ultimately causing forwarding to stop
- CVE-2025-21599 — Junos OS Evolved: Receipt of specifically malformed IPv6 packets causes kernel memory exhaustion leading to Denial of Service
- CVE-2025-21091 — BIG-IP SNMP vulnerability
- CVE-2025-14027 — Rockwell Automation Recommends Upgrading From 1756-RM2 XT To 1756-RM3 XT
- CVE-2024-39549 — Junos OS and Junos OS Evolved: Receipt of malformed BGP path attributes leads to a memory leak
- CVE-2026-20012 — A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cis
- CVE-2025-20239 — A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Fi
- CVE-2025-20133 — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Authentication Targeted Denial of Service Vulnerability
- CVE-2025-47397 — Improper Release of Memory Before Removing Last Reference in Graphics
- CVE-2026-20105 — A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) So
- CVE-2026-20014 — A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an
- CVE-2025-25199 — BCryptGenerateSymmetricKey memory leak
- CVE-2026-4247 — TCP: remotely exploitable DoS vector (mbuf leak)
- CVE-2026-33856 — Missing Release of Memory after Effective Lifetime in MolotovCherry Android-ImageMagick7
- CVE-2026-33852 — Missing Release of Memory after Effective Lifetime in MolotovCherry Android-ImageMagick7
- CVE-2026-24828 — Memory leak in is-Engine
- CVE-2025-53537 — LibHTP's memory leak with lzma can lead to resource starvation
- CVE-2025-47935 — Multer vulnerable to Denial of Service via memory leaks from unclosed streams
Recently published
- CVE-2026-16028 — Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table
- CVE-2026-18313 — rpcapd memory leak in libpcap before 1.10.7
- CVE-2026-18076 — IBM i is Affected By Multiple Vulnerabilities in Debug Server
- CVE-2026-13148 — Memory leak in scan method
- CVE-2026-20281 — Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability
- CVE-2026-14697 — IPv6 Neighbor Solicitation packet leak causes TX pool exhaustion denial of service
- CVE-2026-14696 — Ethernet bridge RX packet leak enables denial of service via RX buffer-pool exhaustion
- CVE-2026-38819 — Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaus
- CVE-2026-79771 — Nokogiri before 1.19.3 Memory Leak via XSLT Transform
- CVE-2026-59295 — Micrometer instrumentation of Apache HttpAsyncClient DoS vulnerability
- CVE-2026-12999 — Infineon Airoc Wi-Fi driver leaks TX buffers on send failure, leading to permanent pool exhaustion
- CVE-2026-76235 — Cockpit-ws: cockpit: cockpit-ws: unauthenticated remote memory leak via cockpitlang cookie in send_login_html
- CVE-2026-52734 — ZEBRA: Unbounded memory leak in mempool download pipeline via timeout path cancel_handles retention
- CVE-2026-73565 — @hono/node-server: Unauthenticated memory-leak DoS via aborted WebSocket handshake
- CVE-2026-19382 — Almico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leak
- CVE-2026-56818 — Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state
- CVE-2026-54876 — Client-Side Memory Leak in OCSP Response Checking
- CVE-2026-63252 — In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message ch
- CVE-2026-10774 — PSA key-slot leak in Bluetooth Mesh subnet deletion leading to resource-exhaustion DoS
- CVE-2026-12932 — A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 all