Cyber Posture

CWE · MITRE source

CWE-772Missing Release of Resource after Effective Lifetime

Abstraction: Base · CVEs in our corpus: 449

The product does not release a resource after its effective lifetime has ended, i.e., after the resource is no longer needed.

Last updated: 20 May 2026 08:06 UTC

NIST 800-53 r5 controls that address this weakness (1)AI

Control Title Family Why it addresses this CWE
SC-10Network DisconnectSCEnsures network resources are released once the session ends or becomes inactive, closing the window for missing-release weaknesses.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2021-228836.97.50.89432021-03-03
CVE-2003-01325.10.00.85002003-04-11
CVE-2017-144954.77.50.53322017-10-03
CVE-2024-20481 KEV3.85.80.11122024-10-23
CVE-1999-11273.37.50.30031999-12-31
CVE-2020-93753.27.50.28042020-03-25
CVE-2017-5507 UPD2.27.50.11402017-03-24
CVE-2015-7701 UPD2.27.50.12412017-08-07
CVE-2001-08302.07.50.08962001-12-06
CVE-2007-0897 UPD2.07.50.07882007-02-16
CVE-2017-11641 UPD2.09.80.00452017-07-26
CVE-2017-14138 UPD2.09.80.00222017-09-04
CVE-2017-150322.09.80.00322017-10-05
CVE-2020-121342.09.80.00522020-04-24
CVE-2020-358762.09.80.00512020-12-31
CVE-2023-410942.010.00.00082023-10-04
CVE-2018-191321.95.90.11352018-11-09
CVE-2008-2122 UPD1.87.50.04732008-05-09
CVE-2017-11170 UPD1.88.80.00352017-07-11
CVE-2017-11310 UPD1.88.80.00392017-07-13
CVE-2017-12641 UPD1.88.80.00242017-08-07
CVE-2017-12642 UPD1.88.80.00352017-08-07
CVE-2017-12644 UPD1.88.80.00562017-08-07
CVE-2017-12662 UPD1.88.80.00222017-08-07
CVE-2017-12663 UPD1.88.80.00212017-08-07