CWE-401
CVEs classified under CWE-401, newest first.
139 CVEsRSS
CVE-2026-38819Medium· 5.3Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.
Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.
CVE-2026-47888High· 7.5A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 -…
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 -…
CVE-2026-52734Medium· 5.3ZEBRA is a Zcash node written entirely in Rust
ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transactions after verification reaches the outer RATE_LIMIT_DELAY timeout. In zebrad/src/compo…
CVE-2026-73565Medium· 5.3@hono/node-server allows running the Hono application on Node.js
@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain th…
CVE-2026-19382Low· 2.3A weakness has been identified in Almico Speedfan 4.52
A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attack can only be exe…
CVE-2026-56818Medium· 6.5Netty is an asynchronous, event-driven network application framework
Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, b…
CVE-2026-54876High· 7.5⚖ disputedIssue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…
Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…
CVE-2026-10774Low· 2.4Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown
Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_B…
CVE-2026-12932High· 7.1A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets
A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets
CVE-2026-67437High· 7.5OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)
CVE-2026-67430Medium· 5.3MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood
CVE-2026-64356Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: xfs: fix memory leak in xfs_dqinode_metadir_create() If xfs_metadir_create() fails in xfs_dqinode_metadir_create(), the current code returns directly, leaking the allo…
In the Linux kernel, the following vulnerability has been resolved: xfs: fix memory leak in xfs_dqinode_metadir_create() If xfs_metadir_create() fails in xfs_dqinode_metadir_create(), the current code returns directly, leaking the allo…
CVE-2026-64328Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix DMA fence leak In ffs_dmabuf_transfer(), a ffs_dma_fence object is kmalloc'd, with the underlying dma_fence later initialized by dma_fence_init(…
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix DMA fence leak In ffs_dmabuf_transfer(), a ffs_dma_fence object is kmalloc'd, with the underlying dma_fence later initialized by dma_fence_init(…
CVE-2026-64336Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: USB: serial: keyspan_pda: fix information leak The write() callback is supposed to return the number of characters accepted or a negative errno
In the Linux kernel, the following vulnerability has been resolved: USB: serial: keyspan_pda: fix information leak The write() callback is supposed to return the number of characters accepted or a negative errno. Since the addition of …
CVE-2026-66011Low· 3.3ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided
ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to …
GHSA-6vxp-gfwf-hcr9Low· 2.9ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.
ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.
GHSA-7c7m-fpjw-gwcqLow· 2.9ImageMagick: Memory Leak in color transformation to log colorspace when operation fails
ImageMagick: Memory Leak in color transformation to log colorspace when operation fails
GHSA-j8rh-v2r8-v94xLow· 2.9ImageMagick: Memory Leak in hough lines operation when an operation fails
ImageMagick: Memory Leak in hough lines operation when an operation fails
GHSA-99w9-hv66-rfv7Low· 2.9ImageMagick: Memory Leak in JNG encoder when a blob could not be opened
ImageMagick: Memory Leak in JNG encoder when a blob could not be opened
GHSA-jfq9-q63x-rc63Low· 2.9ImageMagick: Memory Leak in TIFF encoder when an allocation fails
ImageMagick: Memory Leak in TIFF encoder when an allocation fails
GHSA-h7f2-f9cc-h2gvLow· 3.7ImageMagick: Memory Leak in YUV decoder when opening of blob fails
ImageMagick: Memory Leak in YUV decoder when opening of blob fails
GHSA-r628-69v2-2f9cLow· 2.9ImageMagick: Memory Leak in MIFF encoder when allocaton fails
ImageMagick: Memory Leak in MIFF encoder when allocaton fails
GHSA-m596-67p7-69whLow· 2.9ImageMagick: Memory leak in VIFF encoder when allocation fails
ImageMagick: Memory leak in VIFF encoder when allocation fails
GHSA-h58x-r7f7-rh84Low· 3.7ImageMagick: Memory Leak in ICON decoder when allocation fails
ImageMagick: Memory Leak in ICON decoder when allocation fails
GHSA-h5r4-w88w-7ccrLow· 2.5ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified
ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified
CVE-2024-7708High· 7.5Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests
GHSA-9mqv-5hh9-4cggMedium· 5.3Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
CVE-2026-64072Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: nvme: fix bio leak on mapping failure The local bio is always NULL, so we'd leak the bio if the integrity mapping failed
In the Linux kernel, the following vulnerability has been resolved: nvme: fix bio leak on mapping failure The local bio is always NULL, so we'd leak the bio if the integrity mapping failed. Just get it directly from the request.
CVE-2026-64139Medium· 5.5In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit 299f962c0b02 ("ksmbd: use check_add_overflow() to prevent u16 DACL size overflow") added …
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit 299f962c0b02 ("ksmbd: use check_add_overflow() to prevent u16 DACL size overflow") added …
CVE-2026-44806Medium· 5.3Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.
Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.