VYPR

CWE-672

Operation on a Resource after Expiration or Release

ClassDraft

Description

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

Hierarchy (View 1000)

CVEs mapped to this weakness (98)

page 4 of 5
  • CVE-2022-45292MedDec 9, 2022
    risk 0.34cvss 5.3epss 0.01

    User invites for Funkwhale v1.2.8 do not permanently expire after being used for signup and can be used again after an account has been deleted.

  • CVE-2026-45005MedMay 11, 2026
    risk 0.32cvss 6.0epss 0.00

    OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to remain valid after rotation and reload. Attackers with previously valid webhook route secrets can continue authenticating requests and invoking configured…

  • CVE-2026-31875MedMar 11, 2026
    risk 0.31cvss 5.9epss 0.00

    Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.7 and 8.6.33, when multi-factor authentication (MFA) via TOTP is enabled for a user account, Parse Server generates two single-use recovery codes. These…

  • CVE-2023-48220MedFeb 20, 2024
    risk 0.30cvss 5.7epss 0.01

    Decidim is a participatory democracy framework. Starting in version 0.4.rc3 and prior to version 2.0.9 of the `devise_invitable` gem, the invites feature allows users to accept the invitation for an unlimited amount of time through the password reset functionality. This issue…

  • CVE-2024-49955MedOct 21, 2024
    risk 0.29cvss 5.5epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: ACPI: battery: Fix possible crash when unregistering a battery hook When a battery hook returns an error when adding a new battery, then the battery hook is automatically unregistered. However the battery hook…

  • CVE-2026-79010MedAug 25, 2026
    risk 0.28cvss 4.3epss 0.00

    Operation on a resource after expiration or release in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-47060MedSep 20, 2024
    risk 0.28cvss 4.3epss 0.00

    Zitadel is an open source identity management platform. In Zitadel, even after an organization is deactivated, associated projects, respectively their applications remain active. Users across other organizations can still log in and access through these applications, leading to…

  • CVE-2024-31895MedMay 22, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288176.

  • CVE-2024-31894MedMay 22, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288175.

  • CVE-2024-31893MedMay 22, 2024
    risk 0.28cvss 4.3epss 0.00

    IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive calendar information using an expired access token. IBM X-Force ID: 288174.

  • CVE-2026-33463MedMay 28, 2026
    risk 0.27cvss 5.3epss 0.00

    Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-bounded access token to remain usable beyond its intended validity window,…

  • CVE-2026-32244MedMay 19, 2026
    risk 0.27cvss 5.3epss 0.00

    Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unprivileged users who cannot regenerate summaries. This issue has been fixed in…

  • CVE-2024-45244MedAug 25, 2024
    risk 0.27cvss 5.3epss 0.01

    Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do not verify that a request has a timestamp within the expected time window.

  • CVE-2026-47087LowJul 16, 2026
    risk 0.23cvss 3.5epss 0.00

    An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.

  • CVE-2026-1629MedMar 16, 2026
    risk 0.21cvss 4.3epss 0.00

    Mattermost versions 10.11.x <= 10.11.10 Fail to invalidate cached permalink preview data when a user loses channel access which allows the user to continue viewing private channel content via previously cached permalink previews until cache reset or relogin.. Mattermost Advisory…

  • CVE-2022-42838LowFeb 27, 2023
    risk 0.21cvss 3.3epss 0.00

    An issue with app access to camera data was addressed with improved logic. This issue is fixed in macOS Ventura 13. A camera extension may be able to continue receiving video after the app which activated was closed.

  • CVE-2020-15270MedOct 22, 2020
    risk 0.21cvss 4.3epss 0.01

    Parse Server (npm package parse-server) broadcasts events to all clients without checking if the session token is valid. This allows clients with expired sessions to still receive subscription objects. It is not possible to create subscription objects with invalid session…

  • CVE-2024-23332MedJan 19, 2024
    risk 0.19cvss 4.0epss 0.00

    The Notary Project is a set of specifications and tools intended to provide a cross-industry standard for securing software supply chains by using authentic container images and other OCI artifacts. An external actor with control of a compromised container registry can provide…

  • CVE-2026-42955LowJul 22, 2026
    risk 0.17cvss 3.7epss 0.00

    In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records.…

  • CVE-2026-42791LowMay 27, 2026
    risk 0.17cvss 3.7epss 0.00

    Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. OCSP response verification in pubkey_ocsp:verify_response/5 and…