What is CWE-672?
The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.
CWE-672 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Mobile.
Source: MITRE CWE (CWE-672 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity, Confidentiality — Modify Application Data, Read Application Data. If a released resource is subsequently reused or reallocated, then an attempt to use the original resource might allow access to sensitive data that is associated with a different user or entity.
- Other, Availability — Other, DoS: Crash, Exit, or Restart. When a resource is released it might not be in an expected state, later attempts to access the resource may lead to resultant errors that may lead to a crash.
Source: MITRE CWE, common consequences.
How CWE-672 is exploited in the wild
Threadlinqs maps 4 CVEs to CWE-672, published between 2026-02-13 and 2026-10-06. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 high, 2 medium. The highest EPSS score in the set is 0.5% (CVE-2026-55250), the modelled probability of exploitation in the next 30 days. 7 tracked threats reference CWE-672 directly or through a CVE it covers; the most recent is “Gitea 28.x Patches 27 Security Flaws Including Critical SSH Public-Key Authentication Bypass (CVE-2026-103059), SSRF/DNS Rebinding and Actions Approval Bypasses” (2026-10-08). Affected products concentrate in Gitea (1), Linux (1), Sylius (1), among 4 vendors in total.
Vulnerabilities (CVEs)
All 4 CVEs mapped to CWE-672, CISA KEV first, then by CVSS score.
- CVE-2026-23111 — CVSS 7.8 high · EPSS 0.5% · published 2026-02-13
- CVE-2026-53637 — CVSS 6.5 medium · EPSS 0.2% · published 2026-09-08
- CVE-2026-96589 — CVSS 4.3 medium · EPSS 0.2% · published 2026-10-06
- CVE-2026-55250 — EPSS 0.5% · published 2026-09-08
Affected vendors
Threat activity
7 tracked threats cite CWE-672:
- Gitea 28.x Patches 27 Security Flaws Including Critical SSH Public-Key Authentication Bypass (CVE-2026-103059), SSRF/DNS Rebinding and Actions Approval BypassesCRITICAL
- Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)HIGH
- LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)MEDIUM
- Klue OAuth Supply-Chain Breach Enables 'Icarus' Salesforce CRM Data-Theft Extortion CampaignHIGH
- CVE-2026-23111: Linux Kernel nf_tables Use-After-Free Enables Local Privilege Escalation and Container EscapeHIGH
- PinTheft — Linux Kernel RDS Zerocopy FOLL_PIN Refcount Imbalance Chained With io_uring Fixed Buffers For Page-Cache Overwrite And Local Root (Public PoC, Arch Linux Default-Affected)HIGH
- Dead.Letter — CVE-2026-45185 Unauthenticated Pre-Auth RCE in Exim via Use-After-Free in BDAT/GnuTLSCRITICAL
Detection methods (MITRE CWE)
- Automated Static Analysis: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.