CWE-771: Missing Reference to Active Allocated Resource
The product does not properly maintain a reference to a resource that has been allocated, which prevents the resource from being reclaimed.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-20004 — A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust
- CVE-2025-21090 — Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to p
- CVE-2026-3039 — BIND 9 server memory exhaustion during GSS-API TKEY negotiation
- CVE-2024-56343 — IBM Verify Identity Access Digital Credentials denial of service
Recently published
- CVE-2026-3039 — BIND 9 server memory exhaustion during GSS-API TKEY negotiation
- CVE-2026-20004 — A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust
- CVE-2025-21090 — Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to p
- CVE-2024-56343 — IBM Verify Identity Access Digital Credentials denial of service
More specific weaknesses
- CWE-773 — Missing Reference to Active File Descriptor or Handle