CWE-772

High likelihood

Missing Release of Resource after Effective Lifetime

Parent: CWE-404 - Improper Resource Shutdown or Release

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

472 vulnerabilities with CWE-772
CVE-2026-12353 MEDIUM
Rhcs: memory leak during https connection leads to denial of service
CVSS 5.3
CVE-2026-56444 MEDIUM
Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration
CVSS 5.9
CVE-2026-41637 LOW
Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
CVSS 3.7
CVE-2026-36590 HIGH
NanoMQ 0.24.9 - Denial of Service via nni_qos_db_set Function in broker_tcp.c
CVSS 7.5
CVE-2026-15713 MEDIUM
Libsoup: soupcache: libsoup: http/2 frame window exhaustion remote denial of service via memory leak
CVSS 5.9
CVE-2026-54786 MEDIUM
Wasmtime: Leak in WASIp1 `fd_renumber` implementation
CVSS 5.0
CVE-2026-13351 HIGH
net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets
CVSS 7.5
CVE-2026-40209 MEDIUM
PowerDNS DNSdist - Denial of Service via IXFR Queries
CVSS 5.3
CVE-2026-53251 MEDIUM
Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
CVSS 5.5
CVE-2026-53154 MEDIUM
mm/hugetlb: restore reservation on error in hugetlb folio copy paths
CVSS 5.5
CVE-2026-48043 MEDIUM
netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion
CVSS 5.3
CVE-2026-48006 HIGH
Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator
CVSS 7.5
CVE-2026-45536 MEDIUM
Netty: Unix-socket fd receive leaks descriptors when peer sends two at once
CVSS 4.0
CVE-2026-46292 MEDIUM
pmdomain: core: Fix detach procedure for virtual devices in genpd
CVSS 5.5
CVE-2026-45287 MEDIUM
OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse
CVSS 5.5
CVE-2026-9156 MEDIUM
Tanium addressed a denial of service vulnerability in Tanium Server.
CVSS 6.5
CVE-2026-39830 CRITICAL
Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh
CVSS 9.1
CVE-2026-42577 HIGH
Netty: epoll transport denial of service via RST on half-closed TCP connection
CVSS 7.5
CVE-2026-39455 HIGH
BIG-IP 21.1.0+ 21.0.0-21.0.0.1 17.5.0-17.5.1.5 17.1.0-17.1.3.1 16.1.0 - Denial of Service via LDAP Authentication
CVSS 7.5
CVE-2026-35227 HIGH
Improper resource management in CODESYS Modbus TCP Server
CVE-2026-43314 MEDIUM
dm: remove fake timeout to avoid leak request
CVSS 5.5
CVE-2026-43257 MEDIUM
media: cx88: Add missing unmap in snd_cx88_hw_params()
CVSS 5.5
CVE-2026-43054 MEDIUM
scsi: target: tcm_loop: Drain commands in target_reset handler
CVSS 5.5
CVE-2026-3104 HIGH
Memory leak in code preparing DNSSEC proofs of non-existence
CVSS 7.5
CVE-2026-23299 MEDIUM
Bluetooth: purge error queues in socket destructors
CVSS 5.5
Details
Vulnerabilities 472
Exploit Likelihood High