The product releases a resource that is still intended to be used by itself or another actor.
Volume of CVEs assigned to CWE-826 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-53322HIGH In the Linux kernel, the following vulnerability has been resolved:
vfio/pci: Clean up DMABUFs before disabling function
On device shutdown, make vfio_pci_core_close_device() cal | Jun 26, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-33526HIGH Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a re | Mar 26, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-32748HIGH Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denia | Mar 26, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-45984HIGH In the Linux kernel, the following vulnerability has been resolved:
gfs2: Fix use-after-free in iomap inline data write path
The inline data buffer head (dibh) is being released | May 27, 2026 | 7.8 | 29 | NO | NO |
CVE-2026-31663HIGH In the Linux kernel, the following vulnerability has been resolved:
xfrm: hold dev ref until after transport_finish NF_HOOK
After async crypto completes, xfrm_input_resume() call | Apr 24, 2026 | 7.8 | 29 | NO | NO |
CVE-2025-31115HIGH XZ Utils provide a general-purpose data-compression library plus command-line tools. In XZ Utils 5.3.3alpha to 5.8.0, the multithreaded .xz decoder in liblzma has a bug where inval | Apr 3, 2025 | 8.7 | 29 | NO | NO |
CVE-2023-1297HIGH Consul and Consul Enterprise's cluster peering implementation contained a flaw whereby a peer cluster with service of the same name as a local service could corrupt Consul state, r | Jun 2, 2023 | 7.5 | 22 | NO | NO |
CVE-2024-51727HIGH Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x contains a feature that could enable attackers to invalidate a legitimate user's session and cause a denial-of-serv | Dec 6, 2024 | 7.5 | 21 | NO | NO |
In wxWidgets before 3.2.7, a crash can be triggered in wxWidgets apps when connections are refused in wxWebRequestCURL. | Apr 16, 2025 | 3.7 | 15 | NO | NO |
hostapd fails to process crafted RADIUS packets properly. When hostapd authenticates wi-fi devices with RADIUS authentication, an attacker in the position between the hostapd and t | Mar 12, 2025 | 3.7 | 14 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.