Cyber Resilience

CWE · MITRE source

CWE-401Missing Release of Memory after Effective Lifetime

Abstraction: Variant · CVEs in our corpus: 1,890

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

Last updated: 22 August 2026 22:22 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.PS-06
  • SA-11 Developer Testing and Evaluation
  • SA-8 Security and Privacy Engineering Principles
  • SA-15 Development Process, Standards, and Tools
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2018-0158 KEV 8.88.60.07242018-03-28
CVE-2016-6304 8.27.50.63032016-09-26
CVE-2020-13934 8.27.50.64122020-07-14
CVE-2016-4232 7.67.50.36462016-07-13
CVE-2022-0742 7.59.10.05042022-03-18
CVE-2023-26083 KEV 7.53.30.01262023-04-06
CVE-2024-27388 7.59.80.00962024-05-01
CVE-2024-36911 7.49.80.00612024-05-30
CVE-2024-56779 7.39.80.00532025-01-08
CVE-2024-57947 7.39.80.00442025-01-23
CVE-2025-21954 7.39.80.00462025-04-01
CVE-2026-46289 7.39.80.00462026-06-08
CVE-2025-39948 7.29.80.00272025-10-04
CVE-2019-6128 7.18.80.03872019-01-11
CVE-2019-12265 7.05.30.59802019-08-09
CVE-2021-40633 6.98.80.01642022-06-14
CVE-2022-1012 6.88.20.03892022-08-05
CVE-2023-33718 6.78.80.00722023-05-31
CVE-2019-1708 6.68.60.02042019-05-03
CVE-2019-19078 6.67.50.06622019-11-18
CVE-2020-3189 6.68.60.01802020-05-06
CVE-2020-15254 6.68.10.02782020-10-16
CVE-2020-3373 6.68.60.01922020-10-21
CVE-2020-3572 6.68.60.01762020-10-21
CVE-2021-1313 6.68.60.01952021-02-04