The product releases a resource such as memory or a file so that it can be made available for reuse, but it does not clear or "zeroize" the information contained in the resource before the product performs a critical state transition or makes the resource available for reuse by other entities.
Volume of CVEs assigned to CWE-226 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13585HIGH Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business M | Jul 15, 2026 | 8.2 | 41 | NO | NO |
CVE-2026-47247HIGH libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid i | Jul 21, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-5795HIGH In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable.
Upon returning from the initial checks, there are conditio | Apr 8, 2026 | 7.4 | 30 | NO | NO |
CVE-2025-0647HIGH In certain Arm CPUs, a CPP RCTX instruction executed on one Processing Element (PE) may inhibit TLB invalidation when a TLBI is issued to the PE, either by the same PE or another P | Jan 14, 2026 | 7.9 | 28 | NO | NO |
CVE-2022-39393HIGH Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a line | Nov 10, 2022 | 8.6 | 28 | NO | NO |
CVE-2018-7166HIGH In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory. This method is intended to be safe and only re | Aug 21, 2018 | 7.5 | 26 | NO | NO |
CVE-2019-25560HIGH Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted | Mar 21, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-13108HIGH IBM DB2 Merge Backup for Linux, UNIX and Windows 12.1.0.0 could allow an attacker to access sensitive information in memory due to the buffer not properly clearing resources. | Feb 17, 2026 | 7.5 | 24 | NO | NO |
CVE-2019-25571MEDIUM MediaMonkey 4.1.23 contains a denial of service vulnerability that allows local attackers to crash the application by opening a specially crafted MP3 file containing an excessively | Mar 21, 2026 | 6.2 | 23 | NO | NO |
CVE-2026-32960MEDIUM SD-330AC and AMC Manager provided by silex technology, Inc. contain an issue with a sensitive information in resource not removed before reuse. An attacker may login to the device | Apr 20, 2026 | 6.5 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.