The product does not properly maintain a reference to a resource that has been allocated, which prevents the resource from being reclaimed.
Volume of CVEs assigned to CWE-771 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3039HIGH BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constr | May 20, 2026 | 7.5 | 36 | NO | NO |
CVE-2023-20244HIGH A vulnerability in the internal packet processing of Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 2100 Series Firewalls could allow an unauthenticated, remote | Nov 1, 2023 | 8.6 | 28 | NO | NO |
CVE-2021-34720HIGH A vulnerability in the IP Service Level Agreements (IP SLA) responder and Two-Way Active Measurement Protocol (TWAMP) features of Cisco IOS XR Software could allow an unauthenticat | Sep 9, 2021 | 8.6 | 27 | NO | NO |
CVE-2026-20004HIGH A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust the available memory of an affected device.
This vulnera | Mar 25, 2026 | 7.4 | 25 | NO | NO |
CVE-2025-21090MEDIUM Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of service via local access. | Aug 12, 2025 | 6.5 | 21 | NO | NO |
CVE-2024-56343MEDIUM IBM Verify Identity Access Digital Credentials 24.06 could allow an authenticated user to crash the service with a specially crafted POST request. | Jun 6, 2025 | 6.5 | 17 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.