CWE-772

CWE-772 · 7 records · 5 with a public proof-of-concept

Records the NVD classes under CWE-772, highest CVSS first.

  1. HIGH 7.5CVE-2026-79677

    Missing release of resource after effective lifetime, Comparison using wrong factors vulnerability in Apache Tomcat allows a denial of service as a result of lost time outs for asynchronous WebSocket writes. This issue affects Apache Tomcat: from 11.0.0-M1 …

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-92983public PoC

    InternLM LMDeploy through 0.17.0 in DistServe prefill/decode disaggregation mode fails to release scheduler sessions because the proxy uses user-facing session IDs instead of internal scheduler keys. Unauthenticated attackers can send completion requests to th…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-63128public PoC

    RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.0.0, the rmcp crate's stateful Streamable HTTP server in crates/rmcp/src/transport/streamable_http_server/tower.rs allows an unauthenticated client to send a well-formed JSON-RPC POST that…

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-61387public PoC

    In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems…

    milo

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.9CVE-2026-85718public PoC

    The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. From 3.0.8 until 3.0.12, a client with maxConnections or maxConnectionsPerHost set above zero leaks one connection permit when…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 5.5CVE-2026-97686

    Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properly release allocated kernel memory and system file descriptors before terminating the calling application. Fixed in Version 26.09.

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5.3CVE-2026-94625public PoC

    vLLM through 0.29.0 contains a resource exhaustion vulnerability in MooncakeConnector where rejected prefill requests create ownerless transfer placeholders that are never reclaimed. Attackers can send rejected requests to exhaust sender task pools, causing va…

    AI risk analysis on Exploit-DB.ai →