CWE-459— Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.— MITRE CWE catalog
221 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-459page 5 of 5
- CVE-2026-72714MEDIUMCVSS 6.3EG 6.32026-08-24
Rocq Prover does not restore the universe graph's copy of the universe checking flag when a module that locally disabled the check is closed. Local Unset Universe Checking inside a module is expected to last only until the module ends, and…
- CVE-2026-75943LOWCVSS 2.6EG 2.62026-09-14
A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's traffic may pass wit…
- CVE-2026-75944LOWCVSS 2.6EG 2.62026-09-14
A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorrect access control …
- CVE-2026-75945LOWCVSS 2.6EG 2.62026-09-14
A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
- CVE-2026-7639HIGHCVSS 7.8EG 7.82026-07-10
Software installed and run as a non-privileged user may conduct a sequence of improper GPU system calls causing use after free, which helps in facilitating unprivileged memory access from a shader code. Triggering failure path in the MM…
- CVE-2026-77037HIGHCVSS 7.5EG 7.52026-08-28
multer is a middleware for handling multipart/form-data in Node.js. In version 2.2.0, when a disk-backed upload is aborted or truncated before the write stream finishes, multer's disk storage engine removes the visible file but does not cl…
- CVE-2026-77761MEDIUMCVSS 6.3EG 6.32026-08-21
A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into the MISP event generated from a subsequent document when the same parser instance is reused…
- CVE-2026-78600LOWCVSS 3.5EG 3.52026-09-02
Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (CAPEC-122). Authentication credentials persist after a cross-namespace association has been denied by RBAC enforcement, …
- CVE-2026-78903LOWCVSS 3.1EG 3.12026-08-25
Incomplete cleanup in SiteIsolation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-78947MEDIUMCVSS 6.5EG 6.52026-08-25
Incomplete cleanup in Chromium in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Low)
- CVE-2026-79265MEDIUMCVSS 5.3EG 5.32026-08-25
Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromi…
- CVE-2026-82236LOWCVSS 3.1EG 3.12026-08-28
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to th…
- CVE-2026-82237LOWCVSS 3.1EG 3.12026-08-28
filebrowser through 2.63.23 does not remove share records when a shared file is renamed (only deletion triggers share cleanup). The share record is keyed by path, so it survives the rename and remains dormant (returning 404 while the path …
- CVE-2026-85043CRITICALCVSS 9.1EG 9.12026-09-03
Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access restrictions via crafted network traffic. (Chromium security severity: High)
- CVE-2026-87436MEDIUMCVSS 6.5EG 6.52026-09-09
Incomplete cleanup in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass web origin policy via a crafted Chrome extension. (Chromium security severity: Medium)
- CVE-2026-87446MEDIUMCVSS 6.5EG 6.52026-09-09
Incomplete cleanup in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted Chrome extension. (Chromium security severity: Medium)
- CVE-2026-87549MEDIUMCVSS 6.5EG 6.52026-09-09
Incomplete cleanup in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-87776HIGHCVSS 7.5EG 7.52026-09-11
compression is a Node.js and Express compression middleware. In versions before 1.8.2, when a client aborts the connection while a compressed response is still being sent, the zlib stream created to compress that response is never destroye…
- CVE-2026-88932MEDIUMCVSS 5.3EG 5.32026-09-14
multer is a Node.js middleware for handling multipart/form-data uploads. In versions 2.2.0 through 2.3.0, when a request using disk storage is aborted mid-upload, file writes that complete after multer has already run its abort cleanup are…
- CVE-2026-91730LOWCVSS 3.1EG 3.12026-09-15
Incomplete cleanup in GetUserMedia in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain cross-origin data via a crafted HTML page. (Chromium s…
- CVE-2026-9693LOWCVSS 3.5EG 3.52026-08-17
Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a previously removed user who is later re-invited to the team to view…
Map vulnerabilities like CWE-459 to your infrastructure
EchelonGraph correlates every CVE — across CWE-459 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →