CWE-772: Missing Release of Resource after Effective Lifetime
The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.
82 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-20481 — A vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco F
- CVE-2025-65947 — thread-amount is Vulnerable to Resource Exhaustion (Memory and Handle Leaks) on Windows and macOS
- CVE-2025-22891 — BIG-IP PEM Vulnerability
- CVE-2024-52303 — aiohttp memory leak when middleware is enabled when requesting a resource with a non-allowed method
- CVE-2024-39562 — Junos OS Evolved: A high rate of SSH connections causes a Denial of Service
- CVE-2026-20082 — A vulnerability in the handling of the embryonic connection limits in Cisco Secure Firewall Adaptive Security Appliance
- CVE-2025-30256 — A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A spe
- CVE-2025-36128 — IBM MQ denial of service
- CVE-2025-27421 — Goroutine Leak in Abacus SSE Implementation
- CVE-2024-49769 — Waitress has a denial of service leading to high CPU usage/resource exhaustion
- CVE-2026-69664 — httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
- CVE-2026-2359 — Multer vulnerable to Denial of Service via resource exhaustion
- CVE-2026-71380 — httpd applies no timeout while receiving a request body, parking a worker on a stalled client
- CVE-2026-13505 — Zeroisation of sensitive key material on garbage collection relies on finalization
- CVE-2026-39455 — BIG-IP Configuration utility vulnerability
- CVE-2026-35227 — Improper resource management in CODESYS Modbus TCP Server
- CVE-2025-36071 — IBM Db2 denial of service
- CVE-2024-10396 — Fileserver crash and possible information leak on StoreACL/FetchACL
- CVE-2026-20124 — Cisco IOS XE Software SNMP Denial of Service Vulnerability
- CVE-2026-3104 — Memory leak in code preparing DNSSEC proofs of non-existence
Recently published
- CVE-2026-18149 — undici vulnerable to Denial of Service via orphaned RetryHandler response body
- CVE-2026-69664 — httpd parks a request worker indefinitely on a malformed chunk size sent after the headers
- CVE-2026-71380 — httpd applies no timeout while receiving a request body, parking a worker on a stalled client
- CVE-2026-77384 — libp2p: Circuit relay v2 server reservation refresh leaks abort listeners and allows remote resource exhaustion
- CVE-2026-59654 — Apache CloudStack: DoS caused by database connections leak
- CVE-2026-73508 — Netty: Memory Leak in DNS Record Decoder via Malformed Domain Names
- CVE-2026-73215 — The coturn server can end in a state where it does not accept more requests with "even-port" enabled.
- CVE-2026-11811 — Socket file-descriptor leak in UpdateHub OTA client start_coap_client() leading to resource-exhaustion DoS
- CVE-2026-13505 — Zeroisation of sensitive key material on garbage collection relies on finalization
- CVE-2026-49343 — Klever-Go KVM: Throttler slot leak in trie account-data sync causes epoch bootstrap / state sync DoS
- CVE-2026-20124 — Cisco IOS XE Software SNMP Denial of Service Vulnerability
- CVE-2026-61387 — In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fa
- CVE-2026-64607 — Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS
- CVE-2026-12353 — Rhcs: memory leak during https connection leads to denial of service
- CVE-2026-56444 — Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration
- CVE-2026-41637 — Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
- CVE-2026-15713 — Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak
- CVE-2026-54786 — Wasmtime: Leak in WASIp1 `fd_renumber` implementation
- CVE-2026-13351 — net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets
- CVE-2026-45536 — Netty: Unix-socket fd receive leaks descriptors when peer sends two at once