What is CWE-401?
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
CWE-401 is a variant-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of Medium. Applicable platforms: Not Language-Specific; C; C++.
Source: MITRE CWE (CWE-401 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Availability — DoS: Crash, Exit, or Restart, DoS: Instability, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory). Most memory leaks result in general product reliability problems, but if an attacker can intentionally trigger a memory leak, the attacker might be able to launch a denial of service attack (by crashing or hanging the program) or take advantage of other unexpected program behavior resulting from a low memory condition.
- Other — Reduce Performance
Source: MITRE CWE, common consequences.
How CWE-401 is exploited in the wild
Threadlinqs maps 12 CVEs to CWE-401, published between 2026-06-23 and 2026-09-21. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 4 high, 3 medium, 5 low. The highest EPSS score in the set is 0.6% (CVE-2026-56819), the modelled probability of exploitation in the next 30 days. 6 tracked threats reference CWE-401 directly or through a CVE it covers; the most recent is “CVE-2026-54876 — OpenSSL Client-Side Memory Leak in OCSP Response Checking (Denial of Service)” (2026-08-06). Affected products concentrate in ImageMagick (4), zephyrproject (3), vllm-project (2), among 6 vendors in total.
Vulnerabilities (CVEs)
All 12 CVEs mapped to CWE-401, CISA KEV first, then by CVSS score.
- CVE-2026-56819 — CVSS 7.5 high · EPSS 0.6% · published 2026-07-21
- CVE-2026-93436 — CVSS 7.5 high · EPSS 0.5% · published 2026-09-17
- CVE-2026-94627 — CVSS 7.5 high · EPSS 0.4% · published 2026-09-21
- CVE-2026-13474 — CVSS 7.5 high · EPSS 0.4% · published 2026-06-30
- CVE-2026-56116 — CVSS 6.5 medium · EPSS 0.1% · published 2026-06-23
- CVE-2026-15892 — CVSS 5.3 medium · EPSS 0.2% · published 2026-09-13
- CVE-2026-12999 — CVSS 5.3 medium · EPSS 0.2% · published 2026-08-22
- CVE-2026-56365 — CVSS 3.7 low · EPSS 0.2% · published 2026-06-30
- CVE-2026-66011 — CVSS 3.3 low · EPSS 0.1% · published 2026-07-25
- CVE-2026-61870 — CVSS 2.9 low · EPSS 0.1% · published 2026-07-11
- CVE-2026-10774 — CVSS 2.4 low · published 2026-08-02
- CVE-2026-56364 — CVSS 1.9 low · EPSS 0.1% · published 2026-06-30
Affected vendors
- ImageMagick — 4 CVEs
- zephyrproject — 3 CVEs
- vllm-project — 2 CVEs
- NetScaler — 1 CVE
- NetworkConfiguration — 1 CVE
- netty — 1 CVE
Threat activity
6 tracked threats cite CWE-401:
- CVE-2026-54876 — OpenSSL Client-Side Memory Leak in OCSP Response Checking (Denial of Service)HIGH
- CitrixBleed-Class NetScaler ADC/Gateway SAML AuthnRequest Memory Disclosure (CVE-2026-8451) Exploited Within 24 Hours of DisclosureCRITICAL
- CVE-2026-8451: Memory Overread in Citrix NetScaler ADC/Gateway SAML IdP ('CitrixBleed'-class, CVSS 8.8) — Exploited Within 24 Hours of DisclosureHIGH
- CitrixBleed 2.0: CVE-2026-8451 NetScaler SAML IDP Memory Overread Under Active ExploitationCRITICAL
- Node.js June 2026 Security Release — 12 Vulnerabilities Across 22.x/24.x/26.x Including Two High-Severity TLS Authentication Bypass and WebCrypto DoS Flaws (CVE-2026-48618, CVE-2026-48933)HIGH
- BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)HIGH
Mitigations
- Implementation / Libraries or Frameworks: Choose a language or tool that provides automatic memory management, or makes manual memory management less error-prone. For example, glibc in Linux provides protection against free of invalid pointers. When using Xcode to target OS X or iOS, enable automatic reference counting (ARC) [REF-391]. To help correctly and consistently manage memory when programming in C++, consider using a smart pointer class such as std::auto_ptr (defined by ISO/IEC ISO/IEC 14882:2003), std::shared_ptr and std::unique_ptr (specified by an upcoming revision of the C++ standard, informally referred to as C++ 1x
- Architecture and Design: Use an abstraction library to abstract away risky APIs. Not a complete solution.
- Architecture and Design, Build and Compilation: Consider using the Boehm-Demers-Weiser garbage collector (bdwgc), which can help avoid leaks.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Fuzzing: Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with random inputs, it is often capable of generating unexpected results such as crashes, memory corruption, or resource consumption. Fuzzing effectively produces repeatable test cases that clearly indicate bugs, which helps developers to diagnose the issues.
- Automated Dynamic Analysis: Use tools that are integrated during compilation to insert runtime error-checking mechanisms related to memory safety errors, such as AddressSanitizer (ASan) for C/C++ [REF-1518] or valgrind [REF-480].
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.