Threadlinqs IntelligenceStart free

Weakness · ClassCWE-672

CWE-672: Operation on a Resource after Expiration or Release

Class

As of 2026-10-10, CWE-672 (Operation on a Resource after Expiration or Release) underlies 4 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 7 tracked threats.

CVEs
4Mapped to CWE-672
CISA KEV
0None listed yet
Critical
0CVSS v3 critical CVEs
Threats
7Tracked campaigns citing it
Likelihood
—MITRE likelihood of exploit

Last updated:

What is CWE-672?

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

CWE-672 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Mobile.

Source: MITRE CWE (CWE-672 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity, Confidentiality — Modify Application Data, Read Application Data. If a released resource is subsequently reused or reallocated, then an attempt to use the original resource might allow access to sensitive data that is associated with a different user or entity.
  • Other, Availability — Other, DoS: Crash, Exit, or Restart. When a resource is released it might not be in an expected state, later attempts to access the resource may lead to resultant errors that may lead to a crash.

Source: MITRE CWE, common consequences.

How CWE-672 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-672, published between 2026-02-13 and 2026-10-06. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 high, 2 medium. The highest EPSS score in the set is 0.5% (CVE-2026-55250), the modelled probability of exploitation in the next 30 days. 7 tracked threats reference CWE-672 directly or through a CVE it covers; the most recent is “Gitea 28.x Patches 27 Security Flaws Including Critical SSH Public-Key Authentication Bypass (CVE-2026-103059), SSRF/DNS Rebinding and Actions Approval Bypasses” (2026-10-08). Affected products concentrate in Gitea (1), Linux (1), Sylius (1), among 4 vendors in total.

Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-672, CISA KEV first, then by CVSS score.

Affected vendors

  • Gitea — 1 CVE
  • Linux — 1 CVE
  • Sylius — 1 CVE
  • macropay-solutions — 1 CVE

Threat activity

7 tracked threats cite CWE-672:

Detection methods (MITRE CWE)

  • Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.