CWE-404: Improper Resource Shutdown or Release
The product does not release or incorrectly releases a resource before it is made available for re-use.
578 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-29771 — Netmaker: Denial of Service via Server Shutdown Endpoint
- CVE-2026-1876 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series Ethernet module
- CVE-2025-8761 — INSTAR 2K+/4K Backend IPC Server denial of service
- CVE-2025-55102 — A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A special
- CVE-2025-4749 — D-Link DI-7003GV2 Factory Reset backup.asp sub_4983B0 denial of service
- CVE-2025-41399 — SCTP Vulnerability
- CVE-2025-24811 — A vulnerability has been identified in SIMATIC S7-1200 CPU 1211C AC/DC/Rly (6ES7211-1BE40-0XB0), SIMATIC S7-1200 CPU 121
- CVE-2025-22846 — BIG-IP SIP Vulnerability
- CVE-2025-0492 — D-Link DIR-823X FUN_00412244 null pointer dereference
- CVE-2024-4791 — Contemporary Control System BASrouter BACnet BASRT-B Application Protocol Data Unit denial of service
- CVE-2025-5867 — RT-Thread lwp_syscall.c csys_sendto null pointer dereference
- CVE-2025-58473 — AutomationDirect CLICK PLUS Improper Resource Shutdown or Release
- CVE-2025-57882 — AutomationDirect CLICK PLUS Improper Resource Shutdown or Release
- CVE-2025-52982 — Junos OS: MX Series: When specific SIP packets are processed the MS-MPC will crash
- CVE-2025-20127 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 3100 and 4200 Series TLS Cipher Denial of Service Vulnerability
- CVE-2025-1103 — D-Link DIR-823X HTTP POST Request set_wifi_blacklists null pointer dereference
- CVE-2024-28252 — CoreWCF NetFraming based services can leave connections open when they should be closed
- CVE-2026-1875 — Denial-of-Service (DoS) vulnerability in Ethernet function of MELSEC iQ-F Series EtherNet/IP module
- CVE-2026-11317 — Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of Service Via CIP
- CVE-2026-10069 — Shibby Tomato miniupnpd resource consumption
Recently published
- CVE-2026-41869 — Apache Nutch: Unauthenticated forced shutdown and job interruption in Nutch Server (Nutch REST API)
- CVE-2026-86515 — vgmstream txtp txtp_parser.c add_entry resource consumption
- CVE-2026-86511 — java-json-tools jackson-coreutils JacksonUtils.java BigDecimal.toPlainString resource consumption
- CVE-2026-86319 — java-json-tools json-patch Patch Operation JsonPatch.java JsonPatch.apply resource consumption
- CVE-2026-85407 — Eleveo Quality Management Conversation events denial of service
- CVE-2026-85100 — 2FastLabs agent-squad Streaming Agent Response Workflow orchestrator.ts AgentSquad.routeRequest resource consumption
- CVE-2026-84887 — simular-ai Agent-S Model-generated GUI Action Execution Workflow grounding.py denial of service
- CVE-2026-84886 — simular-ai Agent-S OCR HTTP API ocr_server.py ImageData resource consumption
- CVE-2026-84885 — simular-ai Agent-S CodeAgent code_agent.py denial of service
- CVE-2026-84856 — rowboatlabs rowboat Composio Webhook Endpoint route.ts req.json denial of service
- CVE-2026-84833 — ntegrals openbrowser Browser Agent Message Construction agent.ts resource consumption
- CVE-2026-84427 — zhayujie CowAgent Bash Tool bash.py denial of service
- CVE-2026-84425 — zhayujie CowAgent Browser Tool browser_tool.py BrowserTool denial of service
- CVE-2026-84288 — NousResearch hermes-agent ACP Prompt Workflow session.py HermesACPAgent.prompt denial of service
- CVE-2026-84287 — NousResearch hermes-agent Session Chat api_server.py denial of service
- CVE-2026-82821 — FLVMeta AMF Object Parsing amf.c amf_object_get null pointer dereference
- CVE-2026-82803 — armink struct2json JSON Deserialization s2jdef.h S2J_STRUCT_GET_string_ELEMENT null pointer dereference
- CVE-2026-82669 — klaussilveira GitList XML Parsing CommandLine.php SimpleXMLElement denial of service
- CVE-2026-82605 — BareBones BBEdit Lasso Language Tokenizer infinite loop
- CVE-2026-82604 — BareBones BBEdit Java Language recursion