VYPR

CWE-404

Improper Resource Shutdown or Release

ClassDraftLikelihood: Medium

Description

The product does not release or incorrectly releases a resource before it is made available for re-use.

When a resource is created or allocated, the developer is responsible for properly releasing the resource as well as accounting for all potential paths of expiration or invalidation, such as a set period of time or revocation.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-125 · CAPEC-130 · CAPEC-131 · CAPEC-494 · CAPEC-495 · CAPEC-496 · CAPEC-666

CVEs mapped to this weakness (826)

page 22 of 42
  • CVE-2023-5255MedOct 3, 2023
    risk 0.29cvss 4.4epss 0.00

    For certificates that utilize the auto-renew feature in Puppet Server, a flaw exists which prevents the certificates from being revoked.

  • CVE-2023-2646MedMay 11, 2023
    risk 0.29cvss 4.5epss 0.00

    A vulnerability has been found in TP-Link Archer C7v2 v2_en_us_180114 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component GET Request Parameter Handler. The manipulation leads to denial of service. The attack can only be…

  • CVE-2023-0907MedFeb 18, 2023
    risk 0.29cvss 4.4epss 0.00

    A vulnerability, which was classified as problematic, has been found in Filseclab Twister Antivirus 8.17. Affected by this issue is the function 0x220017 in the library ffsmon.sys of the component IoControlCode Handler. The manipulation leads to denial of service. An attack has…

  • CVE-2026-94094MedSep 20, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extensions/canvas/src/host/server.ts of the component Canvas Host Route. Executing a manipulation can lead to denial of service. The attack can be launched remotely.…

  • CVE-2026-92413MedSep 16, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in Artifex MuPDF up to b6d17493700c621c0e70036980a6ebd06d2202c9. Affected by this vulnerability is the function pdf_open_filter of the file pdf-stream.c of the component PDF Xref Loading. Executing a manipulation can lead to null pointer dereference. The…

  • CVE-2026-92356MedSep 16, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the file basic_functions.ts of the component Update Components. Executing a manipulation can lead to resource consumption. The attack can be launched remotely. The…

  • CVE-2026-90816MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be…

  • CVE-2026-90712MedSep 14, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file src/services/api/xaiOAuthCallback.ts of the component xAI OAuth Callback Handler. The manipulation of the argument Error leads to denial of service. Remote…

  • CVE-2026-85407MedSep 4, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations//events of the component Conversation Handler. The manipulation of the argument labels results in denial of service. The…

  • CVE-2026-85100MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript/src/orchestrator.ts of the component Streaming Agent Response Workflow. The manipulation results in…

  • CVE-2026-84887MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-generated GUI Action Execution Workflow. The manipulation leads to denial of service. Remote exploitation of the…

  • CVE-2026-84885MedSep 3, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads to denial of service. The attack can be launched remotely. The exploit has been disclosed to the…

  • CVE-2026-84833MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa961750da8e2f4a75d87c5c75c8. Affected by this vulnerability is an unknown functionality of the file packages/core/src/agent/agent.ts of the component Browser Agent Message Construction. Performing a…

  • CVE-2026-84427MedSep 2, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing a manipulation can lead to denial of service. The attack can be launched remotely. The exploit has been…

  • CVE-2026-84288MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such manipulation leads to denial of service. The attack may be performed from…

  • CVE-2026-84287MedSep 1, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component Session Chat Interface. This manipulation causes denial of service. The attack is possible to be carried…

  • CVE-2026-82605MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in BareBones BBEdit up to 15.5.5. The affected element is an unknown function of the component Lasso Language Tokenizer. Such manipulation leads to infinite loop. The attack can be executed remotely. Upgrading to version 16.0 is sufficient to fix…

  • CVE-2026-82604MedAug 31, 2026
    risk 0.28cvss 4.3epss 0.00

    A flaw has been found in BareBones BBEdit up to 15.5.5. Impacted is an unknown function of the component Java Language Module. This manipulation causes uncontrolled recursion. Remote exploitation of the attack is possible. Upgrading to version 16.0 is recommended to address this…

  • CVE-2026-82552MedAug 30, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in Linux Foundation Magma 1.9.0. Affected by this vulnerability is an unknown functionality of the file tasks/ngap/ngap_amf.c of the component gNB Termination Handler. The manipulation leads to denial of service. The attack is possible…

  • CVE-2026-78250MedAug 24, 2026
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was identified in bytebot-ai bytebot 0.0.1. The affected element is an unknown function of the component Agent Execution Workflow. Such manipulation leads to infinite loop. The attack may be performed from remote. The exploit is publicly available and might be…