CWE-404

Medium likelihood

Improper Resource Shutdown or Release

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product does not release or incorrectly releases a resource before it is made available for re-use.

750 vulnerabilities with CWE-404
CVE-2026-38641 HIGH
relibc - Denial of Service via DSO::mmap_and_copy Shared Library Loading
CVSS 7.5
CVE-2026-54280 HIGH
AIOHTTP: Payload Response Resources Are Not Closed After Mid-Body Disconnect
CVSS 7.5
CVE-2026-11317 HIGH
Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of Service Via CIP
CVE-2026-45174 HIGH
Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initialization
CVSS 7.8
CVE-2026-47213 MEDIUM
BoxLite: Timeout Bypass Vulnerability
CVSS 6.5
CVE-2026-11312 LOW
bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity
CVSS 3.3
CVE-2026-10802 MEDIUM
keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption
CVSS 4.3
CVE-2026-10775 LOW
sgl-project SGLang Cache data_hash denial of service
CVSS 3.6
CVE-2026-10705 LOW
dask HLL hyperloglog.py nunique_approx resource consumption
CVSS 3.1
CVE-2026-10650 MEDIUM
warmcat libwebsockets SSH Protocol sshd.c lws_ssh_parse_plaintext resource consumption
CVSS 5.3
CVE-2026-10298 LOW
whisper.cpp <= 1.8.2 - Null Pointer Dereference in whisper_model_load
CVSS 3.3
CVE-2026-10295 LOW
SourceCodester Customer Review App 1.0 - Denial of Service via Name/Comment Argument Manipulation
CVSS 3.3
CVE-2026-10224 MEDIUM
NousResearch hermes-agent Webhook Endpoint feishu.py _handle_webhook_request resource consumption
CVSS 5.3
CVE-2026-10201 LOW
Assimp UV Channel FBXExporter.cpp WriteObjects divide by zero
CVSS 3.3
CVE-2026-10199 LOW
Assimp glTF2Asset.h LazyDict null pointer dereference
CVSS 3.3
CVE-2026-10198 LOW
Assimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference
CVSS 3.3
CVE-2026-10197 LOW
Assimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference
CVSS 3.3
CVE-2026-10190 MEDIUM
Tenda W12 Web Management httpd cgiSysWebTimeoutSet denial of service
CVSS 6.5
CVE-2026-10156 MEDIUM
Open5GS nf-instances Endpoint nnrf-handler.c handle_amf_info resource consumption
CVSS 4.3
CVE-2026-10117 MEDIUM
Open5GS nghttp2-server.c ogs_pool_id_calloc denial of service
CVSS 4.3
CVE-2026-10116 MEDIUM
Open5GS ue-authentications Endpoint ogs-timer.c ogs_sbi_xact_add denial of service
CVSS 4.3
CVE-2026-10115 MEDIUM
Open5GS Shared NF-profile nnrf-handler.c denial of service
CVSS 4.3
CVE-2026-10113 MEDIUM
Open5GS Shared NF-profile nnrf-handler.c denial of service
CVSS 4.3
CVE-2026-10069 HIGH
Shibby Tomato miniupnpd resource consumption
CVSS 7.5
CVE-2026-45090 HIGH
Dalfox: Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode)
CVSS 7.5
Details
Vulnerabilities 750
Exploit Likelihood Medium