VulnSea

CWE-401

CVEs classified under CWE-401, newest first.

139 CVEsRSS

CVE-2026-38819Medium· 5.3
3w ago

Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.

Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticated attacker on the captive portal network to exhaust all available memory on the device within minutes.

SunlitEPSS 0.18%via NVD
CVE-2026-47888High· 7.5
3w ago

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 -…

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 -…

Twilightvmware · spring_frameworkEPSS 0.32%via NVD
CVE-2026-52734Medium· 5.3
1mo ago

ZEBRA is a Zcash node written entirely in Rust

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transactions after verification reaches the outer RATE_LIMIT_DELAY timeout. In zebrad/src/compo…

Sunlitzebrad · zebradEPSS 0.37%via NVD
CVE-2026-73565Medium· 5.3
1mo ago

@hono/node-server allows running the Hono application on Node.js

@hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route with a missing or malformed Sec-WebSocket-Key header causes src/websocket.ts to retain th…

Sunlithonojs · node-serverEPSS 0.39%via NVD
CVE-2026-19382Low· 2.3
1mo ago

A weakness has been identified in Almico Speedfan 4.52

A weakness has been identified in Almico Speedfan 4.52. This affects the function KiSystemCall64 in the library speedfan.sys of the component MSR Index Handler. Executing a manipulation can lead to memory leak. The attack can only be exe…

SunlitEPSS 0.12%via NVD
CVE-2026-56818Medium· 6.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec clears retained partial aggregate state when the maxNestedArrayDepth limit is exceeded, b…

Sunlitnetty · io.netty:netty-codec-redisEPSS 0.28%via NVD
CVE-2026-54876High· 7.5⚖ disputed
1mo ago

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response that contains no single response entries. Impact summary: An attacker can leak an attacker…

TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.26%via NVD
CVE-2026-10774Low· 2.4
1mo ago

Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown

Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys_create() imports the Private Beacon Key into a PSA key slot under CONFIG_BT_MESH_PRIV_B…

SunlitEPSS 0.27%via NVD
CVE-2026-12932High· 7.1
1mo ago

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

TwilightOpenVPN · OpenVPNEPSS 0.42%via CVEORG
CVE-2026-67437High· 7.5
1mo ago

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)

TwilightOliveTin · github.com/OliveTin/OliveTinEPSS 0.35%via GHSA
CVE-2026-67430Medium· 5.3
1mo ago

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood

Sunlitmcp · mcpEPSS 0.31%via GHSA
CVE-2026-64356Medium· 5.5
1mo ago

In the Linux kernel, the following vulnerability has been resolved: xfs: fix memory leak in xfs_dqinode_metadir_create() If xfs_metadir_create() fails in xfs_dqinode_metadir_create(), the current code returns directly, leaking the allo…

In the Linux kernel, the following vulnerability has been resolved: xfs: fix memory leak in xfs_dqinode_metadir_create() If xfs_metadir_create() fails in xfs_dqinode_metadir_create(), the current code returns directly, leaking the allo…

Sunlitlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-64328Medium· 5.5
1mo ago

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix DMA fence leak In ffs_dmabuf_transfer(), a ffs_dma_fence object is kmalloc'd, with the underlying dma_fence later initialized by dma_fence_init(…

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: Fix DMA fence leak In ffs_dmabuf_transfer(), a ffs_dma_fence object is kmalloc'd, with the underlying dma_fence later initialized by dma_fence_init(…

Sunlitlinux · linux_kernelEPSS 0.16%via NVD
CVE-2026-64336Medium· 5.5
1mo ago

In the Linux kernel, the following vulnerability has been resolved: USB: serial: keyspan_pda: fix information leak The write() callback is supposed to return the number of characters accepted or a negative errno

In the Linux kernel, the following vulnerability has been resolved: USB: serial: keyspan_pda: fix information leak The write() callback is supposed to return the number of characters accepted or a negative errno. Since the addition of …

Sunlitlinux · linux_kernelEPSS 0.12%via NVD
CVE-2026-66011Low· 3.3
1mo ago

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to …

SunlitEPSS 0.09%via NVD
GHSA-6vxp-gfwf-hcr9Low· 2.9
1mo ago

ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.

ImageMagick: Memory Leak in TIFF encoder when a temporary file could not be created.

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-7c7m-fpjw-gwcqLow· 2.9
1mo ago

ImageMagick: Memory Leak in color transformation to log colorspace when operation fails

ImageMagick: Memory Leak in color transformation to log colorspace when operation fails

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-j8rh-v2r8-v94xLow· 2.9
1mo ago

ImageMagick: Memory Leak in hough lines operation when an operation fails

ImageMagick: Memory Leak in hough lines operation when an operation fails

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-99w9-hv66-rfv7Low· 2.9
1mo ago

ImageMagick: Memory Leak in JNG encoder when a blob could not be opened

ImageMagick: Memory Leak in JNG encoder when a blob could not be opened

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-jfq9-q63x-rc63Low· 2.9
1mo ago

ImageMagick: Memory Leak in TIFF encoder when an allocation fails

ImageMagick: Memory Leak in TIFF encoder when an allocation fails

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-h7f2-f9cc-h2gvLow· 3.7
1mo ago

ImageMagick: Memory Leak in YUV decoder when opening of blob fails

ImageMagick: Memory Leak in YUV decoder when opening of blob fails

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-r628-69v2-2f9cLow· 2.9
1mo ago

ImageMagick: Memory Leak in MIFF encoder when allocaton fails

ImageMagick: Memory Leak in MIFF encoder when allocaton fails

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-m596-67p7-69whLow· 2.9
1mo ago

ImageMagick: Memory leak in VIFF encoder when allocation fails

ImageMagick: Memory leak in VIFF encoder when allocation fails

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-h58x-r7f7-rh84Low· 3.7
1mo ago

ImageMagick: Memory Leak in ICON decoder when allocation fails

ImageMagick: Memory Leak in ICON decoder when allocation fails

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-h5r4-w88w-7ccrLow· 2.5
1mo ago

ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified

ImageMagick: Memory Leak in TIFF encoder when invalid tiff:tile-geometry is specified

SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
CVE-2024-7708High· 7.5
2mo ago

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

Eclipse Jetty: DoS attack triggering OutOfMemory with 100-Continue requests

Twilighteclipse · org.eclipse.jetty:jetty-serverEPSS 0.44%via GHSA
GHSA-9mqv-5hh9-4cggMedium· 5.3
2mo ago

Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake

Sunlithono · @hono/node-servervia GHSA
CVE-2026-64072Medium· 5.5
2mo ago

In the Linux kernel, the following vulnerability has been resolved: nvme: fix bio leak on mapping failure The local bio is always NULL, so we'd leak the bio if the integrity mapping failed

In the Linux kernel, the following vulnerability has been resolved: nvme: fix bio leak on mapping failure The local bio is always NULL, so we'd leak the bio if the integrity mapping failed. Just get it directly from the request.

Sunlitlinux · linux_kernelEPSS 0.13%via NVD
CVE-2026-64139Medium· 5.5
2mo ago

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit 299f962c0b02 ("ksmbd: use check_add_overflow() to prevent u16 DACL size overflow") added …

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow Commit 299f962c0b02 ("ksmbd: use check_add_overflow() to prevent u16 DACL size overflow") added …

Sunlitlinux · linux_kernelEPSS 0.14%via NVD
CVE-2026-44806Medium· 5.3
2mo ago

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

Missing release of memory after effective lifetime in Windows Cryptographic Services allows an unauthorized attacker to deny service over a network.

Sunlitmicrosoft · windows_10_1607EPSS 1.2%via NVD
CWE-401 vulnerabilities (CVEs) — page 2 · VulnSea