CWE-672Class

Operation on a Resource after Expiration or Release

Draft in the CWE catalog · 53 CVEs mapped

53
CVEs mapped
6.6
Median CVSS
What it is

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

Recent examples
8.1cvss
CVE-2026-61699

CVE-2026-61699 - HIGH Severity Vulnerability

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches any peer's config.yml, a Blocked host retains full overlay reachability to every peer under its CA (and internal services on the mesh) for up to 30d (agent) / 365d (mobile). An attacker who exfiltrates host.key+host.crt can run stock slackhq/nebula directly, ignore the agent's 403/410 poll responses, and stay connected after the operator revokes the host. Operator-visible state (UI shows blocked, audit log records it) is misleading. This issue has been patched in version 0.7.1.

HIGHno explanation yet
0%
epss
6.5cvss
CVE-2026-85044

CVE-2026-85044 - MEDIUM Severity Vulnerability

Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted HTML page. (Chromium security severity: Medium)

MEDIUMno explanation yet
0%
epss
none
CVE-2026-19538

CVE-2026-19538 - UNKNOWN Severity Vulnerability

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

no explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-672
Abstraction
Class
Structure
Simple
Status
Draft
References (1)