Cyber Resilience

CWE · MITRE source

CWE-672Operation on a Resource after Expiration or Release

Abstraction: Class · CVEs in our corpus: 87

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

Last updated: 21 August 2026 14:15 UTC

Control responseHuman-reviewed

Answering this weakness across the control lifecycle, from our framework cross-walks.

Prevent
Stop it (NIST 800-53 / CSF Protect)
  • PR.AA-05
  • PR.PS-06
  • AC-2 Account Management
  • AC-3 Access Enforcement
Detect
Catch it (CSF Detect / Respond)

Harden
Shrink the surface (DISA STIG)
  • 1 hardening rule · 1 OS baseline
Validate
Prove the fix (OWASP ASVS)

NIST 800-53 r5 controls that address this weakness (0)AI-assisted

Control Title Family Why it addresses this CWE
No NIST controls proposed yet.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2019-17638 8.09.40.11142020-07-09
CVE-2020-12043 7.79.80.02102020-06-29
CVE-2020-24030 7.79.80.02672020-09-02
CVE-2026-33278 7.59.80.01272026-05-20
CVE-2023-41094 7.410.00.00572023-10-04
CVE-2024-23638 7.46.50.60052024-01-24
CVE-2021-23995 6.88.80.01212021-06-24
CVE-2013-10075 6.89.10.00362026-05-08
CVE-2022-22755 6.68.80.00592022-12-22
CVE-2021-33020 6.38.20.00632022-04-01
CVE-2024-47571 6.38.10.00912025-01-14
CVE-2025-38290 6.38.80.00192025-07-10
CVE-2020-13530 6.27.50.02062020-12-11
CVE-2021-37185 6.27.50.02062022-02-09
CVE-2021-37204 6.27.50.02182022-02-09
CVE-2026-43585 6.28.10.00542026-05-06
CVE-2019-15691 6.17.20.04722019-12-26
CVE-2022-22197 6.17.50.01102022-04-14
CVE-2017-0544 6.07.80.00862017-04-07
CVE-2020-25221 6.07.80.00672020-09-10
CVE-2022-22332 6.07.50.00762022-04-01
CVE-2022-30256 6.07.50.00902022-11-19
CVE-2024-27308 6.07.50.00892024-03-06
CVE-2009-3547 5.97.00.04892009-11-04
CVE-2024-397925.97.50.00632024-08-14