Cyber Posture

CWE · MITRE source

CWE-404Improper Resource Shutdown or Release

Abstraction: Class · CVEs in our corpus: 658

The product does not release or incorrectly releases a resource before it is made available for re-use.

When a resource is created or allocated, the developer is responsible for properly releasing the resource as well as accounting for all potential paths of expiration or invalidation, such as a set period of time or revocation.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (4)AI

Control Title Family Why it addresses this CWE
SC-10Network DisconnectSCMandates explicit shutdown of the network connection at session conclusion, directly addressing improper resource release.
SC-4Information in Shared System ResourcesSCRequires proper shutdown/release procedures that include overwriting or isolating data to block unintended transfer via reused system objects.
CP-5Contingency Plan UpdateCPContingency plan updates incorporate proper resource shutdown and release steps, preventing attackers from leveraging incomplete cleanup during recovery scenarios.
SI-17Fail-safe ProceduresSIProcedures can mandate orderly shutdown or release of resources when failures occur, preventing improper resource handling after a fault.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2018-8120 KEV9.07.00.94152018-05-09
CVE-2018-8405 KEV6.67.80.49992018-08-15
CVE-2018-8406 KEV6.67.80.49992018-08-15
CVE-2018-8639 KEV5.77.80.34872018-12-12
CVE-2018-8611 KEV4.57.80.16362018-12-12
CVE-2017-6627 KEV4.17.50.10182017-09-07
CVE-2018-84503.98.80.35062018-11-14
CVE-2024-05463.35.30.36562024-01-15
CVE-2018-84103.17.80.26412018-09-13
CVE-2022-442672.66.50.22092023-02-06
CVE-2017-56502.37.50.12672017-04-17
CVE-2024-511792.37.50.13542024-11-12
CVE-2023-244442.19.80.01582023-01-26
CVE-2025-11031.96.50.09602025-02-07
CVE-2018-82101.87.80.03272018-06-14
CVE-2019-17081.88.60.00942019-05-03
CVE-2020-260701.88.60.01712020-11-12
CVE-2022-257621.88.60.00652022-05-13
CVE-2024-316111.89.10.00232024-06-10
CVE-2017-11451.78.60.00502017-03-20
CVE-2018-82131.77.80.02832018-06-14
CVE-2018-83081.76.60.05942018-07-11
CVE-2019-17061.78.60.00462019-05-03
CVE-2019-152621.77.50.02932019-10-16
CVE-2019-198861.77.50.04012020-01-21