Cyber Posture

CWE · MITRE source

CWE-459Incomplete Cleanup

Abstraction: Base · CVEs in our corpus: 182

The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Last updated: 09 May 2026 03:25 UTC

NIST 800-53 r5 controls that address this weakness (6)AI

Showing the 5 most specific. Generic controls that address many weakness types are collapsed below.

Control Title Family Why it addresses this CWE
SI-12Information Management and RetentionSIOperational retention schedules mandate complete cleanup of temporary or residual sensitive data after use.
SI-14Non-persistenceSITermination of the non-persistent artifact guarantees cleanup of temporary state, directly countering incomplete cleanup weaknesses.
SI-17Fail-safe ProceduresSIFail-safe procedures can explicitly require cleanup of temporary state, resources, or privileges on failure to avoid leaving the system in an inconsistent state.
SC-4Information in Shared System ResourcesSCMandates complete sanitization during cleanup so that shared resources (memory, caches, buffers) do not retain data across subjects.
SR-12Component DisposalSREnforces complete cleanup and sanitization steps during disposal, closing gaps that leave data remnants on retired components.
Show 1 more broadly-applicable controls
SI-21Information RefreshSIThe explicit delete step when information is no longer needed implements the cleanup that this weakness omits.

Top CVEs of this weakness type, ranked by Risk Priority

CVE Risk CVSS EPSS Published
CVE-2021-393276.55.30.90942021-09-17
CVE-2017-170906.37.50.80582017-12-02
CVE-2023-364682.59.90.09242023-06-29
CVE-2025-316502.17.50.09552025-04-28
CVE-2005-17442.09.80.00732005-05-24
CVE-2018-189242.08.80.03382018-11-04
CVE-2020-134512.09.80.00582021-01-07
CVE-2021-329282.09.80.00342021-06-16
CVE-2021-457062.09.80.00422021-12-27
CVE-2021-453302.09.80.01132022-02-09
CVE-2022-453472.09.80.00122022-12-22
CVE-2026-282682.09.80.00042026-02-27
CVE-2022-15521.98.80.02262022-08-31
CVE-2019-181911.88.80.00762019-12-16
CVE-2019-250161.88.80.01022021-01-28
CVE-2020-244891.88.80.00072021-06-09
CVE-2024-282651.89.10.00192024-11-01
CVE-2025-216091.89.10.00372025-01-03
CVE-2017-03031.67.50.02442017-10-27
CVE-2018-182811.67.80.00422018-10-30
CVE-2018-199611.67.80.00182018-12-08
CVE-2020-01831.67.80.00022020-06-11
CVE-2020-59871.67.80.00052020-10-02
CVE-2021-224281.68.10.00202021-08-02
CVE-2022-06461.67.80.00112022-02-18