CWE-459: Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
90 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-28268 — Vikunja Vulnerable to Account Takeover via Password Reset Token Reuse
- CVE-2025-59781 — BIG-IP DNS cache vulnerability
- CVE-2025-21609 — SiYuan has an arbitrary file deletion vulnerability
- CVE-2025-43711 — Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upo
- CVE-2026-34263 — Missing authentication check in SAP Commerce cloud configuration
- CVE-2026-78947 — Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin
- CVE-2025-6338 — Possible denial of service with multiple incoming connections to a Schannel based server with a TLS backend
- CVE-2026-85043 — Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access
- CVE-2026-3304 — Multer vulnerable to Denial of Service via incomplete cleanup
- CVE-2026-52736 — ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache
- CVE-2025-0032 — Improper cleanup in AMD CPU microcode patch loading could allow an attacker with local administrator privilege to load m
- CVE-2025-2260 — Eclipse ThreadX NetX Duo HTTP component server denial of service
- CVE-2025-0726 — Eclipse ThreadX NetX Duo HTTP server denial of service
- CVE-2026-79265 — Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised
- CVE-2025-66467 — Apache CloudStack: MinIO policy remains intact on bucket deletion
- CVE-2026-7639 — GPU DDK - Page UAF read in PMMETA_PROTECT heap memory
- CVE-2025-0473 — Incomplete Cleanup vulnerability in PMB platform
- CVE-2024-36353 — Insufficient clearing of GPU global memory could allow a malicious process running on the same GPU to read left over mem
- CVE-2026-77037 — multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
- CVE-2026-33232 — AutoGPT: Unauthenticated DoS via Disk Space Exhaustion
Recently published
- CVE-2026-87549 — Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engi
- CVE-2026-87436 — Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engine
- CVE-2026-87446 — Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social eng
- CVE-2026-85043 — Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access
- CVE-2026-78600 — Incomplete Cleanup in Elastic Cloud on Kubernetes Leading to Unauthorized Cross-Namespace Credential Retention
- CVE-2026-77037 — multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
- CVE-2026-82237 — filebrowser through 2.63.23 Stale Share Link via File Rename
- CVE-2026-82236 — File Browser 2.63.6 through 2.63.23 Share Link Exposure via File Deletion
- CVE-2026-78947 — Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engin
- CVE-2026-79265 — Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised
- CVE-2026-78903 — Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromise
- CVE-2026-72714 — Rocq Prover through 9.2.0 Universe Checking State Desynchronised After Module Close
- CVE-2026-77761 — Cross-Document Parser State Contamination in misp-stix
- CVE-2026-67442 — FUXA Business Logic Flaw: Role Deletion Without User Assignment Cleanup
- CVE-2026-52736 — ZEBRA: Block suppression via NU5 same-header body poisoning of sent-hash cache
- CVE-2026-52733 — ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip
- CVE-2026-9693 — Mattermost thread memberships persist after team removal, exposing private channel thread metadata on re-invite
- CVE-2026-19474 — @fastify/multipart vulnerable to Denial of Service via temporary file leak on aborted upload
- CVE-2026-19730 — Podman: podman: quadlet install --replace non-truncating write retains removed host-access directives
- CVE-2026-20712 — Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disc