CWE-672: Operation on a Resource after Expiration or Release
The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
52 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-55669 — BIG-IP HTTP/2 vulnerability
- CVE-2026-31875 — Parse Server MFA recovery codes not consumed after use
- CVE-2024-47571 — An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker
- CVE-2026-30978 — Heap-use-after-free in CIccCmm::AddXform()
- CVE-2025-6031 — Insecure device pairing in end of life Amazon Cloud Cam
- CVE-2026-33278 — Possible arbitrary code execution during DNSSEC validation
- CVE-2026-43585 — OpenClaw < 2026.4.15 - Bearer Token Validation Bypass via Stale SecretRef Resolution
- CVE-2013-10075 — Apache::Session versions through 1.94 for Perl re-creates deleted sessions
- CVE-2024-27308 — Mio's tokens for named pipes may be delivered after deregistration
- CVE-2026-55250 — Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagged Caches
- CVE-2025-69415 — In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly a
- CVE-2026-2379 — Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled
- CVE-2026-19538 — Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
- CVE-2026-61699 — nebula-mesh: Certificate revocation is never enforced at the mesh
- CVE-2025-21117 — Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local atta
- CVE-2025-10060 — MongoDB may be susceptible to Invariant Failure in Transactions due Upsert Operation
- CVE-2026-50575 — BetterDesk has a replay behavior vulnerability when devices are deleted
- CVE-2026-68481 — Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
- CVE-2026-79010 — Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote
- CVE-2026-56314 — Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint
Recently published
- CVE-2026-53637 — Sylius: Cart FormComponent allows modification or deletion of an already-completed order
- CVE-2026-55250 — Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagged Caches
- CVE-2026-61699 — nebula-mesh: Certificate revocation is never enforced at the mesh
- CVE-2026-85044 — Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker lever
- CVE-2026-19538 — Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS
- CVE-2026-79010 — Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote
- CVE-2026-44725 — EMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code execution
- CVE-2026-52733 — ZEBRA: Persistent on-disk corruption of Sapling/Orchard subtree roots after chain fork via pop_tip
- CVE-2026-50575 — BetterDesk has a replay behavior vulnerability when devices are deleted
- CVE-2026-68481 — Apache CXF: Revocation bypass in DefaultEncryptingOAuthDataProvider
- CVE-2026-42955 — Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
- CVE-2026-47087 — An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A
- CVE-2026-56314 — Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint
- CVE-2026-2379 — Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled
- CVE-2026-33463 — Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized File Access
- CVE-2026-42791 — OCSP responder certificate validity period not checked in public_key
- CVE-2026-33278 — Possible arbitrary code execution during DNSSEC validation
- CVE-2026-32244 — Discourse: Cached outdated summaries can leak removed content
- CVE-2026-4053 — post edit time limit is not enforced on some post update operations
- CVE-2026-45005 — OpenClaw < 2026.4.23 - Webhook Route Secret Cache Not Invalidated After Rotation