Threats Tagged 'cwe-772'
View all threats tagged with 'cwe-772'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-772'
Click on any threat for detailed analysis and mitigation recommendations
0 improper handling of exceptional conditions, Missing release of resource after effective lifetime vulnerability in Apache Thrift java bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue. Join the discussion | CVE Database V5 | 10/02/2026, 10:48:38 UTC Added: 10/02/2026, 11:02:49 UTC |
0 CVE-2026-93926 is a high-severity vulnerability in Apache Thrift before version 0.25.0 involving missing release of memory and resources in the THeaderTransport component. This flaw can lead to resource leaks, potentially impacting system stability or availability. The issue is fixed in Apache Thrift version 0.25.0, and users are advised to upgrade to this version to remediate the vulnerability. Join the discussion | CVE Database V5 | 10/02/2026, 10:13:55 UTC Added: 10/02/2026, 14:55:28 UTC |
0 The multicluster engine for Kubernetes provides the foundational components that are necessary for the centralized management of multiple Kubernetes-based clusters across data centers, public clouds, and private clouds. You can use the engine to create new Red Hat OpenShift Container Platform clusters or to bring existing Kubernetes-based clusters under management by importing them. After the clusters are managed, you can use the APIs that are provided by the engine to distribute configuration based on placement policy. Join the discussion | GCVE Database | 09/28/2026, 21:24:10 UTC Added: 07/21/2026, 20:03:21 UTC |
0 Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09. Join the discussion | CVE Database V5 | 09/28/2026, 18:48:23 UTC Added: 09/28/2026, 19:03:27 UTC |
0 Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue. Join the discussion | CVE Database V5 | 09/23/2026, 11:28:03 UTC Added: 09/23/2026, 11:33:33 UTC |
0 CVE-2026-92230 is a high-severity vulnerability in Apache Karaf where static ThreadLocal fields cache XML parser/transformer factories on long-lived container threads. This causes memory from successive bundle ClassLoaders to be retained and unreachable for garbage collection after bundle lifecycle operations, leading to unbounded Metaspace growth and potential denial of service. Join the discussion | CVE Database V5 | 09/17/2026, 18:38:29 UTC Added: 09/17/2026, 19:02:25 UTC |
0 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one connection permit whenever TLS connection establishment fails before the handshake completes. NettyConnectListener removes the partitionKeyLock permit from NettyResponseFuture before every failure path is bound to the channel closeFuture, so an abort can leave the permit unreleased. Repeated failures can permanently lock out one host under a per-host limit or drain the shared pool under a global limit, blocking later requests even when no connection remains open. The default unlimited connection setting is not affected. This issue is fixed in version 3.0.12. Join the discussion | CVE Database V5 | 09/17/2026, 15:58:40 UTC Added: 09/17/2026, 16:47:18 UTC |
0 RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-formed JSON-RPC POST that is not an initialization request, or an initialization request with a mismatched protocol header, causing StreamableHttpService::handle_post to call LocalSessionManager.create_session before validating the message. An early validation failure returns without removing the inserted LocalSessionHandle from LocalSessionManager.sessions, permanently retaining session and channel state for the server process lifetime. Repeated requests can grow the shared session table without bound, degrade legitimate-client latency through lock contention, exhaust memory, and terminate the server. This issue is fixed in version 2.0.0. Join the discussion | CVE Database V5 | 09/16/2026, 14:49:04 UTC Added: 09/16/2026, 15:02:11 UTC |
0 Missing release of resource after effective lifetime in Windows Secure Socket Tunneling Protocol (SSTP) allows an authorized attacker to deny service locally. Join the discussion | CVE Database V5 | 09/08/2026, 17:17:03 UTC Added: 09/08/2026, 17:26:28 UTC |
0 Red Hat has issued a security advisory for Red Hat Hardened Images RPMs, including multiple erlang27 packages, addressing several vulnerabilities. The update provides bug fixes and enhancements for these packages across aarch64 and x86_64 architectures. The advisory references multiple CVEs related to these packages and indicates a high severity level. A patch is available to address these issues. Join the discussion | GCVE Database | 09/02/2026, 08:07:37 UTC Added: 09/03/2026, 15:16:56 UTC |
Showing 1 to 10 of 43 results