Threats Tagged 'cwe-459'
View all threats tagged with 'cwe-459'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-459'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-33232: CWE-459: Incomplete Cleanup in Significant-Gravitas AutoGPTCVE-2026-33232 0 AutoGPT versions 0. 4. 2 through 0. 6. 51 contain a vulnerability where the download_agent_file endpoint creates temporary files that are not deleted after use. This allows an unauthenticated attacker to repeatedly invoke this endpoint, causing uncontrolled disk space consumption. The resulting exhaustion of disk space can lead to failures in the database or other system services, causing a denial of service that renders the AutoGPT backend unavailable. The issue is fixed in version 0. 6. 52. Join the discussion | CVE Database V5 | 05/19/2026, 00:35:50 UTC Added: 05/19/2026, 01:21:39 UTC |
CVE-2026-0427: CWE-459 Incomplete Cleanup in AMD AMD Instinct™ MI210CVE-2026-0427 0 Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources from another Guest VM, potentially resulting in the loss of confidentiality, integrity, or availability. Join the discussion | CVE Database V5 | 05/15/2026, 02:51:22 UTC Added: 05/15/2026, 03:06:41 UTC |
CVE-2026-34263: CWE-459: Incomplete Cleanup in SAP_SE SAP Commerce cloud configurationCVE-2026-34263 0 Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application. Join the discussion | CVE Database V5 | 05/12/2026, 02:20:34 UTC Added: 05/12/2026, 02:51:26 UTC |
CVE-2025-66467: CWE-459 Incomplete Cleanup in Apache Software Foundation Apache CloudStackCVE-2025-66467 0 Missing MinIO policy cleanup on bucket deletion via Apache CloudStack allows users to retain access to buckets which they previously owned. If another user creates a new bucket with the same name, the previous owners can gain unauthorized read and write access to it by using the previously generated access and secret keys. Users are recommended to upgrade to Apache CloudStack versions 4.20.3.0 or 4.22.0.1, or later, which fixes this issue. Join the discussion | CVE Database V5 | 05/08/2026, 12:16:04 UTC Added: 05/08/2026, 12:51:31 UTC |
CVE-2026-35361: CWE-281: Improper Preservation of Permissions in Uutils coreutilsCVE-2026-35361 0 The mknod utility in uutils coreutils fails to handle security labels atomically by creating device nodes before setting the SELinux context. If labeling fails, the utility attempts cleanup using std::fs::remove_dir, which cannot remove device nodes or FIFOs. This leaves mislabeled nodes behind with incorrect default contexts, potentially allowing unauthorized access to device nodes that should have been restricted by mandatory access controls. Join the discussion | CVE Database V5 | 04/22/2026, 16:08:30 UTC Added: 04/22/2026, 16:31:15 UTC |
CVE-2026-6830: CWE-668: Exposure of Resource to Wrong Sphere in nesquena hermes-webuiCVE-2026-6830 0 CVE-2026-6830 is a medium severity vulnerability in nesquena hermes-webui where environment variables from a previously active profile are not cleared before loading a new profile. This allows leakage of sensitive information such as provider API keys across profile contexts, breaking expected security isolation. The vulnerability arises from additive dotenv reload behavior during profile switching. There is no confirmed patch or official remediation available at this time. Join the discussion | CVE Database V5 | 04/21/2026, 21:33:28 UTC Added: 04/21/2026, 21:46:05 UTC |
CVE-2026-28268: CWE-459: Incomplete Cleanup in go-vikunja vikunjaCVE-2026-28268 0 Vikunja is an open-source self-hosted task management platform. Versions prior to 2.1.0 have a business logic vulnerability exists in the password reset mechanism of vikunja/api that allows password reset tokens to be reused indefinitely. Due to a failure to invalidate tokens upon use and a critical logic bug in the token cleanup cron job, reset tokens remain valid forever. This allows an attacker who intercepts a single reset token (via logs, browser history, or phishing) to perform a complete, persistent account takeover at any point in the future, bypassing standard authentication controls. Version 2.1.0 contains a patch for the issue. Join the discussion | CVE Database V5 | 02/27/2026, 20:16:29 UTC Added: 02/27/2026, 20:41:10 UTC |
CVE-2026-3304: CWE-459 in expressjs multerCVE-2026-3304 0 Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available. Join the discussion | CVE Database V5 | 02/27/2026, 15:44:37 UTC Added: 02/27/2026, 15:56:11 UTC |
CVE-2026-28196: CWE-459 in JetBrains TeamCityCVE-2026-28196 0 In JetBrains TeamCity before 2025.11.3 disabling versioned settings left a credentials config on disk Join the discussion | CVE Database V5 | 02/25/2026, 12:57:29 UTC Added: 02/25/2026, 13:26:31 UTC |
CVE-2026-21438: CWE-401: Missing Release of Memory after Effective Lifetime in quic-go webtransport-goCVE-2026-21438 0 webtransport-go is an implementation of the WebTransport protocol. Prior to 0.10.0, an attacker can cause unbounded memory consumption repeatedly creating and closing many WebTransport streams. Closed streams were not removed from an internal session map, preventing garbage collection of their resources. This vulnerability is fixed in v0.10.0. Join the discussion | CVE Database V5 | 02/12/2026, 18:25:34 UTC Added: 02/12/2026, 18:34:12 UTC |
Showing 1 to 10 of 25 results