CWE-460: Improper Cleanup on Thrown Exception
The product does not clean up its state or incorrectly cleans up its state when an exception is thrown, leading to unexpected state or control flow.
22 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2026-20118 — Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Service Vulnerability
- CVE-2024-0316 — Improper cleanup vulnerability in FireEye Endpoint Security
- CVE-2025-32439 — pleezer allows resource exhaustion through uncollected hook script processes
- CVE-2024-12289 — Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service
- CVE-2026-86748 — Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
- CVE-2026-61387 — In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fa
- CVE-2025-30157 — Envoy crashes when HTTP ext_proc processes local replies
- CVE-2026-33481 — Syft improper temporary file cleanup
- CVE-2025-59399 — libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error me
- CVE-2026-48524 — PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
Recently published
- CVE-2026-86748 — Snipe-IT before 8.7.0 Database Wipe via Invalid Backup Archive
- CVE-2026-61387 — In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fa
- CVE-2026-48524 — PyJWT: PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS)
- CVE-2026-40583 — UltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant Halt
- CVE-2026-33481 — Syft improper temporary file cleanup
- CVE-2026-20118 — Cisco IOS-XR NCS 5500 and NCS 5700 Egress Packet Network Interfaces Aligner Interrupt Denial of Service Vulnerability
- CVE-2025-59399 — libocpp before 0.28.0 allows a denial of service (EVerest crash) because a secondary exception is thrown during error me
- CVE-2025-32439 — pleezer allows resource exhaustion through uncollected hook script processes
- CVE-2025-30157 — Envoy crashes when HTTP ext_proc processes local replies
- CVE-2024-12289 — Boundary Controller Incorrectly Handles HTTP Requests On Initialization Which May Lead to a Denial of Service
- CVE-2024-0316 — Improper cleanup vulnerability in FireEye Endpoint Security