CWE-664: Improper Control of a Resource Through its Lifetime
The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.
38 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-20274 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-20269 — Cisco IOS XE Software Security Hardening Release
- CVE-2025-21593 — Junos OS and Junos OS Evolved: On SRv6 enabled devices, an attacker sending a malformed BGP update can cause the rpd to crash
- CVE-2024-37139 — Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a
- CVE-2026-18549 — @fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit
- CVE-2026-20158 — Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities
- CVE-2025-34226 — OpenPLC Runtime v3 Persistent DoS
- CVE-2025-54613 — Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may
- CVE-2025-54612 — Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may
- CVE-2025-54621 — Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory r
- CVE-2025-54619 — Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause i
- CVE-2026-86203 — PocketMine-MP before 5.39.2 Item Duplication via Despawn State
- CVE-2026-79289 — Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote
- CVE-2024-23639 — micronaut-core management endpoints vulnerable to drive-by localhost attack
- CVE-2026-19380 — Mullvad wireguard.sys IOCTL AdapterState reference count
- CVE-2024-41169 — Apache Zeppelin: raft directory listing and file read
Recently published
- CVE-2026-86203 — PocketMine-MP before 5.39.2 Item Duplication via Despawn State
- CVE-2026-20274 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-79289 — Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote
- CVE-2026-18549 — @fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit
- CVE-2026-19380 — Mullvad wireguard.sys IOCTL AdapterState reference count
- CVE-2026-20269 — Cisco IOS XE Software Security Hardening Release
- CVE-2026-20158 — Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities
- CVE-2025-34226 — OpenPLC Runtime v3 Persistent DoS
- CVE-2025-54621 — Iterator failure issue in the WantAgent module. Impact: Successful exploitation of this vulnerability may cause memory r
- CVE-2025-54619 — Iterator failure issue in the multi-mode input module. Impact: Successful exploitation of this vulnerability may cause i
- CVE-2025-54613 — Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may
- CVE-2025-54612 — Iterator failure vulnerability in the card management module. Impact: Successful exploitation of this vulnerability may
- CVE-2024-41169 — Apache Zeppelin: raft directory listing and file read
- CVE-2025-21593 — Junos OS and Junos OS Evolved: On SRv6 enabled devices, an attacker sending a malformed BGP update can cause the rpd to crash
- CVE-2024-37139 — Dell PowerProtect DD, versions prior to 8.0, LTS 7.13.1.0, LTS 7.10.1.30, LTS 7.7.5.40 contain an Improper Control of a
- CVE-2024-23639 — micronaut-core management endpoints vulnerable to drive-by localhost attack
More specific weaknesses
- CWE-118 — Range Error
- CWE-1229 — Creation of Emergent Resource
- CWE-1250 — Improper Preservation of Consistency Between Independent Representations of Shared State
- CWE-221 — Information Loss or Omission
- CWE-372 — Incomplete Internal State Distinction
- CWE-400 — Uncontrolled Resource Consumption
- CWE-404 — Improper Resource Shutdown or Release
- CWE-410 — Insufficient Resource Pool
- CWE-471 — MAID
- CWE-487 — Reliance on Package-level Scope
- CWE-495 — Private Data Structure Returned From A Public Method
- CWE-496 — Public Data Assigned to Private Array-Typed Field
- CWE-501 — Trust Boundary Violation
- CWE-580 — clone() Method Without super.clone()
- CWE-610 — Externally Controlled Reference to a Resource in Another Sphere
- CWE-662 — Improper Synchronization
- CWE-665 — Improper Initialization
- CWE-666 — Operation on Resource in Wrong Phase of Lifetime
- CWE-668 — Exposure of Resource to Wrong Sphere
- CWE-669 — Incorrect Resource Transfer Between Spheres
- CWE-673 — External Influence of Sphere Definition
- CWE-704 — Incorrect Type Conversion or Cast
- CWE-706 — Use of Incorrectly-Resolved Name or Reference
- CWE-911 — Improper Update of Reference Count
- CWE-913 — Improper Control of Dynamically-Managed Code Resources
- CWE-922 — Insecure Storage of Sensitive Information