Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-401'

View all threats tagged with 'cwe-401'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-401

Threats Tagged 'cwe-401'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-73565: CWE-401: Missing Release of Memory after Effective Lifetime in honojs node-serverCVE-2026-73565
0

A memory leak vulnerability exists in honojs node-server versions before 2.0.10. When a WebSocket upgrade request with a missing or malformed Sec-WebSocket-Key header is sent to an upgradeWebSocket route, the request's IncomingMessage is retained indefinitely, causing unbounded memory growth. This can lead to denial of service by exhausting server memory. The issue is fixed in version 2.0.10.

Join the discussion
CVE-2026-63252: CWE-401 in Eclipse Foundation Eclipse MiloCVE-2026-63252
0

Eclipse Milo versions 0.6.0 through 1.1.4 contain a vulnerability in the UASC server transport handlers where partial message chunks are not released upon channel disconnection. This allows a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and disconnecting, potentially causing the server to terminate.

Join the discussion
CVE-2026-67430: CWE-401: Missing Release of Memory after Effective Lifetime in modelcontextprotocol ruby-sdkCVE-2026-67430
0

CVE-2026-67430 is a medium severity vulnerability in the MCP Ruby SDK prior to version 0.23.0. The issue involves the MCP::Server::Transports::StreamableHTTPTransport component not expiring sessions by default, causing unbounded retention of ServerSession objects. This can lead to memory exhaustion in the process due to repeated initialize requests. The vulnerability is fixed in version 0.23.0.

Join the discussion
CVE-2026-58175: CWE-401 Missing Release of Memory after Effective Lifetime in Apache Software Foundation Apache Traffic ServerCVE-2026-58175
0

Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3 contain a memory leak vulnerability when handling HostDB SRV records. This issue is identified as CWE-401, indicating missing release of memory after its effective lifetime. The vulnerability has a high severity with a CVSS score of 7.5 and impacts availability due to memory exhaustion. Upgrading to versions 9.2.15 or 10.1.4 addresses this issue.

Join the discussion
CVE-2026-16318: CWE-401 Missing release of memory after effective lifetime in Amazon s2n-tlsCVE-2026-16318
0

The QUIC transport parameters extension handler in s2n-tls incorrectly uses s2n_alloc instead of s2n_realloc to store the peer's transport parameters. When a TLS 1.3 connection goes through a HelloRetryRequest, the handler is called twice on the same connection. On the second call, s2n_alloc zeroes the existing pointer before allocating new memory, causing the first allocation to be leaked. This can occur during normal QUIC traffic when a client offers a key share group the server does not prefer. An unauthenticated user can amplify the issue by deliberately forcing HelloRetryRequests, causing up to approximately 64 KB of unreachable memory per handshake. Over time, this can lead to increased memory consumption on long-running server processes. The unreachable memory is only reclaimed when the process is restarted. Only server-side QUIC-enabled deployments are affected. Non-QUIC TLS connections are not affected. We recommend you upgrade s2n-tls to version v1.7.6

Join the discussion
CVE-2026-47667: CWE-401: Missing Release of Memory after Effective Lifetime in GreycLab CImgCVE-2026-47667
0

CImg Library versions prior to 4.0.0 contain a memory leak vulnerability in the _load_analyze() function when processing Analyze/NIfTI files. The vulnerability arises because the header_size field is read without bounds checking and used to allocate memory, which is not freed if a file read error occurs. This can lead to large memory allocations being leaked on error paths, causing denial of service due to resource exhaustion. The issue affects files with extensions .hdr, .img, or .nii. Version 4.0.0 addresses this vulnerability.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cwe-401
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses