CWE-664Pillar1 in KEV

Improper Control of a Resource Through its Lifetime

Draft in the CWE catalog · 39 CVEs mapped

39
CVEs mapped
1
In KEV
6.5
Median CVSS
What it is

The product does not maintain or incorrectly maintains control over a resource throughout its lifetime of creation, use, and release.

Recent examples
9.8cvss
CVE-2026-20274

CVE-2026-20274 - CRITICAL Severity Vulnerability

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20274 are related to improper resource control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-664.

CRITICALno explanation yet
1%
epss
3.1cvss
CVE-2026-79289

CVE-2026-79289 - LOW Severity Vulnerability

Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

LOWno explanation yet
0%
epss
7.5cvss
CVE-2026-18549

CVE-2026-18549 - HIGH Severity Vulnerability

@fastify/multipart is a multipart form-data parser for Fastify. In versions from 5.3.0 up to but not including 10.1.1, when the busboy fileSize limit truncates a file part, the plugin clears its internal current-file reference while the underlying stream is still open. If the client then aborts the connection before sending the terminating boundary, the abort cleanup finds no stream to destroy, so saveRequestFiles() never settles, the request handler hangs, and the temporary file already written to disk is never cleaned up. An unauthenticated client can repeat this to permanently leak temporary files and suspended handler executions, leading to disk and event-loop exhaustion. The issue is fixed in @fastify/multipart 10.1.1. Users should upgrade to 10.1.1.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-664
Abstraction
Pillar
Structure
Simple
Status
Draft