Threats Tagged 'cwe-404'
View all threats tagged with 'cwe-404'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-404'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-54280: CWE-404: Improper Resource Shutdown or Release in aio-libs aiohttpCVE-2026-54280 0 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar limited resource, then an attacker may be able to cause resource starvation temporarily until garbage collection or similar closes the file. This vulnerability is fixed in 3.14.1. Join the discussion | CVE Database V5 | 06/22/2026, 16:40:23 UTC Added: 06/22/2026, 17:39:40 UTC |
CVE-2026-11317: CWE-404: Improper Resource Shutdown or Release in Rockwell Automation CompactLogix, ControlLogixCVE-2026-11317 0 CVE-2026-11317 is a high-severity denial of service vulnerability in Rockwell Automation CompactLogix and ControlLogix devices. The issue arises from improper resource shutdown or release when a specially crafted CIP message is processed. Devices with limited memory are more susceptible, potentially causing a major nonrecoverable fault that requires a program download to recover. No patch or official remediation has been confirmed yet. Join the discussion | CVE Database V5 | 06/16/2026, 13:10:19 UTC Added: 06/16/2026, 15:00:27 UTC |
CVE-2026-45174: CWE-404: Improper Resource Shutdown or Release in CyberArk Software, a Palo Alto Networks Company Idira Endpoint Privilege ManagerCVE-2026-45174 0 Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19 Join the discussion | CVE Database V5 | 06/11/2026, 21:22:13 UTC Added: 06/11/2026, 21:31:04 UTC |
CVE-2026-47213: CWE-404: Improper Resource Shutdown or Release in boxlite-ai boxliteCVE-2026-47213 0 Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows users to configure a timeout for services running inside the virtual machine. When the timeout is triggered, Boxlite sends a signal to kill the process. However, instead of using the uncatchable SIGKILL signal, Boxlite uses the catchable SIGALRM signal. Malicious code running inside the sandbox can exploit this vulnerability to continue running after the timeout is triggered, leading to resource exhaustion within the virtual machine and affecting the availability of the Boxlite service. This issue has been patched via commit 28159fc. Join the discussion | CVE Database V5 | 06/10/2026, 22:20:04 UTC Added: 06/10/2026, 22:32:03 UTC |
CVE-2025-9784: Allocation of Resources Without Limits or ThrottlingCVE-2025-9784 0 A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implementation weakness that can be exploited to cause a denial of service (DoS). Join the discussion | GCVE Database | 09/02/2025, 13:37:59 UTC Added: 06/08/2026, 21:20:19 UTC |
CVE-2026-45090: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in hahwul dalfoxCVE-2026-45090 0 CVE-2026-45090 is a race condition vulnerability in hahwul dalfox versions prior to 2.13.0. The issue arises because two sequential worker stages write to the same results channel, which is closed after the first stage, causing the second stage to write to a closed channel. This triggers a Go runtime panic that crashes the dalfox process. In server mode, this crash can be remotely triggered by unauthenticated callers via the REST API if the default configuration is used without an API key and the attacker supplies POST-body data that is reflected by the target. The vulnerability is fixed in version 2.13.0. Join the discussion | CVE Database V5 | 05/27/2026, 17:33:06 UTC Added: 05/27/2026, 17:48:47 UTC |
Showing 1 to 6 of 6 results