CWE-401— Missing Release of Memory after Effective Lifetime (Memory Leak)
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.— MITRE CWE catalog
1,959 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-401page 4 of 40
- CVE-2025-53537HIGHCVSS 7.5EG 7.52025-07-23
LibHTP is a security-aware parser for the HTTP protocol and its related bits and pieces. In versions 0.5.50 and below, there is a traffic-induced memory leak that can starve the process of memory, leading to loss of visibility. To workarou…
- CVE-2025-53020HIGHCVSS 7.5EG 7.52025-07-10
Late Release of Memory after Effective Lifetime vulnerability in Apache HTTP Server. This issue affects Apache HTTP Server: from 2.4.17 up to 2.4.63. Users are recommended to upgrade to version 2.4.64, which fixes the issue.
- CVE-2025-47935HIGHCVSS 7.5EG 7.52025-05-19
Multer is a node.js middleware for handling `multipart/form-data`. Versions prior to 2.0.0 are vulnerable to a resource exhaustion and memory leak issue due to improper stream handling. When the HTTP request stream emits an error, the inte…
- CVE-2025-30658HIGHCVSS 7.5EG 7.52025-04-09
A Missing Release of Memory after Effective Lifetime vulnerability in the Anti-Virus processing of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX…
- CVE-2025-29910HIGHCVSS 7.5EG 7.52025-03-17
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. A memory…
- CVE-2025-1634HIGHCVSS 7.5EG 7.52025-02-26
A flaw was found in the quarkus-resteasy extension, which causes memory leaks when client requests with low timeouts are made. If a client request times out, a buffer is not released correctly, leading to increased memory usage and eventua…
- CVE-2025-27097HIGHCVSS 7.5EG 7.52025-02-20
GraphQL Mesh is a GraphQL Federation framework and gateway for both GraphQL Federation and non-GraphQL Federation subgraphs, non-GraphQL services, such as REST and gRPC, and also databases such as MongoDB, MySQL, and PostgreSQL. When a use…
- CVE-2025-25199HIGHCVSS 7.5EG 7.52025-02-12
go-crypto-winnative Go crypto backend for Windows using Cryptography API: Next Generation (CNG). Prior to commit f49c8e1379ea4b147d5bff1b3be5b0ff45792e41, calls to `cng.TLS1PRF` don't release the key handle, producing a small memory leak e…
- CVE-2025-21091HIGHCVSS 7.5EG 7.52025-02-05
When SNMP v1 or v2c are disabled on the BIG-IP, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- CVE-2025-21599HIGHCVSS 7.5EG 7.52025-01-09
A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Tunnel Driver (jtd) of Juniper Networks Junos OS Evolved allows an unauthenticated network-based attacker to cause Denial of Service. Receipt of specific…
- CVE-2024-8376HIGHCVSS 7.5EG 7.52024-10-11
In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.
- CVE-2024-8626HIGHCVSS 7.5EG 7.52024-10-08
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the …
- CVE-2024-7884HIGHCVSS 7.5EG 7.52024-09-05
When a canister method is called via ic_cdk::call* , a new Future CallFuture is created and can be awaited by the caller to get the execution result. Internally, the state of the Future is tracked and stored in a struct called CallFuture…
- CVE-2024-41172HIGHCVSS 7.5EG 7.52024-07-19
In versions of Apache CXF before 3.6.4 and 4.0.5 (3.5.x and lower versions are not impacted), a CXF HTTP client conduit may prevent HTTPClient instances from being garbage collected and it is possible that memory consumption will continue …
- CVE-2024-39549HIGHCVSS 7.5EG 7.52024-07-11
A Missing Release of Memory after Effective Lifetime vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a malformed BGP Path attribute update which allocates memo…
- CVE-2024-3382HIGHCVSS 7.5EG 7.52024-04-10
A memory leak exists in Palo Alto Networks PAN-OS software that enables an attacker to send a burst of crafted packets through the firewall that eventually prevents the firewall from processing traffic. This issue applies only to PA-5400 S…
- CVE-2024-1394HIGHCVSS 7.5EG 7.52024-03-21
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code, which might lead to a resource exhaustion vulnerability using attacker-controlled inputs. The memory leak happens in github.com/golang-fips/openssl/openssl/rs…
- CVE-2023-33086HIGHCVSS 7.5EG 7.52024-03-04
Transient DOS while processing multiple IKEV2 Informational Request to device from IPSEC server with different identifiers.
- CVE-2023-33084HIGHCVSS 7.5EG 7.52024-03-04
Transient DOS while processing IE fragments from server during DTLS handshake.
- CVE-2024-24148HIGHCVSS 7.5EG 7.52024-02-28
A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
- CVE-2024-27508HIGHCVSS 7.5EG 7.52024-02-27
Atheme 7.2.12 contains a memory leak vulnerability in /atheme/src/crypto-benchmark/main.c.
- CVE-2024-27507HIGHCVSS 7.5EG 7.52024-02-27
libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.
- CVE-2023-33049HIGHCVSS 7.5EG 7.52024-02-06
Transient DOS in Multi-Mode Call Processor due to UE failure because of heap leakage.
- CVE-2024-24267HIGHCVSS 7.5EG 7.52024-02-05
gpac v2.2.1 (fixed in v2.4.0) was discovered to contain a memory leak via the gfio_blob variable in the gf_fileio_from_blob function.
- CVE-2024-24265HIGHCVSS 7.5EG 7.52024-02-05
gpac v2.2.1 was discovered to contain a memory leak via the dst_props variable in the gf_filter_pid_merge_properties_internal function.
- CVE-2024-24259HIGHCVSS 7.5EG 7.52024-02-05
freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.
- CVE-2024-24258HIGHCVSS 7.5EG 7.52024-02-05
freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.
- CVE-2024-22563HIGHCVSS 7.5EG 7.52024-01-19
openvswitch 2.17.8 was discovered to contain a memory leak via the function xmalloc__ in openvswitch-2.17.8/lib/util.c.
- CVE-2024-21611HIGHCVSS 7.5EG 7.52024-01-12
A Missing Release of Memory after Effective Lifetime vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS)…
- CVE-2023-0248HIGHCVSS 7.5EG 7.52023-12-14
An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader's communication memory between the card and reader.
- CVE-2023-38380HIGHCVSS 7.5EG 7.52023-12-12
A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions)…
- CVE-2023-41102HIGHCVSS 7.5EG 7.52023-11-17
An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available mem…
- CVE-2023-5954HIGHCVSS 7.5EG 7.52023-11-09
HashiCorp Vault and Vault Enterprise inbound client requests triggering a policy check can lead to an unbounded consumption of memory. A large number of these requests may lead to denial-of-service. Fixed in Vault 1.15.2, 1.14.6, and 1.13.…
- CVE-2023-44192HIGHCVSS 7.5EG 7.52023-10-13
An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS). On all Junos OS QFX5000 S…
- CVE-2023-40534HIGHCVSS 7.5EG 7.52023-10-10
When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause TMM…
- CVE-2023-5156HIGHCVSS 7.5EG 7.52023-09-25
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
- CVE-2023-28366HIGHCVSS 7.5EG 7.52023-09-01
The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because …
- CVE-2023-4513HIGHCVSS 7.5EG 7.52023-08-24
BT SDP dissector memory leak in Wireshark 4.0.0 to 4.0.7 and 3.6.0 to 3.6.15 allows denial of service via packet injection or crafted capture file
- CVE-2023-32247HIGHCVSS 7.5EG 7.52023-07-24
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the handling of SMB2_SESSION_SETUP commands. The issue results from the lack of control of resource consumption. An atta…
- CVE-2023-31517HIGHCVSS 7.5EG 7.52023-05-23
A memory leak in the component CConsole::Chain of Teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via opening a crafted file.
- CVE-2023-29163HIGHCVSS 7.5EG 7.52023-05-03
When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not eva…
- CVE-2023-28982HIGHCVSS 7.5EG 7.52023-04-17
A Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network based attacker to cause a Denial of Service (DoS). In a …
- CVE-2023-30637HIGHCVSS 7.5EG 7.52023-04-13
Baidu braft 1.1.2 has a memory leak related to use of the new operator in example/atomic/atomic_server. NOTE: installations with brpc-0.14.0 and later are unaffected.
- CVE-2023-26257HIGHCVSS 7.5EG 7.52023-02-27
An issue was discovered in the Connected Vehicle Systems Alliance (COVESA; formerly GENIVI) dlt-daemon through 2.18.8. Dynamic memory is not released after it is allocated in dlt-control-common.c.
- CVE-2023-25566HIGHCVSS 7.5EG 7.52023-02-14
GSS-NTLMSSP is a mechglue plugin for the GSSAPI library that implements NTLM authentication. Prior to version 1.2.0, a memory leak can be triggered when parsing usernames which can trigger a denial-of-service. The domain portion of a usern…
- CVE-2022-45920HIGHCVSS 7.5EG 7.52023-01-26
In Softing uaToolkit Embedded before 1.41, a malformed CreateMonitoredItems request may cause a memory leak.
- CVE-2023-22417HIGHCVSS 7.5EG 7.52023-01-13
A Missing Release of Memory after Effective Lifetime vulnerability in the Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In an IPsec VPN envi…
- CVE-2023-22410HIGHCVSS 7.5EG 7.52023-01-13
A Missing Release of Memory after Effective Lifetime vulnerability in the Juniper Networks Junos OS on MX Series platforms with MPC10/MPC11 line cards, allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). Devices…
- CVE-2022-4743HIGHCVSS 7.5EG 7.52023-01-12
A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x …
- CVE-2022-47941HIGHCVSS 7.5EG 7.52022-12-23
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c omits a kfree call in certain smb2_handle_negotiate error conditions, aka a memory leak.
Map vulnerabilities like CWE-401 to your infrastructure
EchelonGraph correlates every CVE — across CWE-401 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →