# CWE-672: Operation on a Resource after Expiration or Release

> As of 2026-10-10, CWE-672 (Operation on a Resource after Expiration or Release) underlies 4 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 7 tracked threats.

**Last updated:** 2026-10-10

## What is CWE-672?

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

CWE-672 is a class-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; Mobile.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/672.html) (CWE-672 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Integrity, Confidentiality** — Modify Application Data, Read Application Data. If a released resource is subsequently reused or reallocated, then an attempt to use the original resource might allow access to sensitive data that is associated with a different user or entity.
- **Other, Availability** — Other, DoS: Crash, Exit, or Restart. When a resource is released it might not be in an expected state, later attempts to access the resource may lead to resultant errors that may lead to a crash.

_Source: MITRE CWE, common consequences._

## How CWE-672 is exploited in the wild

Threadlinqs maps 4 CVEs to CWE-672, published between 2026-02-13 and 2026-10-06. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 1 high, 2 medium. The highest EPSS score in the set is 0.5% (CVE-2026-55250), the modelled probability of exploitation in the next 30 days. 7 tracked threats reference CWE-672 directly or through a CVE it covers; the most recent is “Gitea 28.x Patches 27 Security Flaws Including Critical SSH Public-Key Authentication Bypass (CVE-2026-103059), SSRF/DNS Rebinding and Actions Approval Bypasses” (2026-10-08). Affected products concentrate in Gitea (1), Linux (1), Sylius (1), among 4 vendors in total.

## Vulnerabilities (CVEs)

All 4 CVEs mapped to CWE-672, CISA KEV first, then by CVSS score.

- [CVE-2026-23111](https://intel.threadlinqs.com/cve/CVE-2026-23111) — CVSS 7.8 high · EPSS 0.5% · published 2026-02-13
- [CVE-2026-53637](https://intel.threadlinqs.com/cve/CVE-2026-53637) — CVSS 6.5 medium · EPSS 0.2% · published 2026-09-08
- [CVE-2026-96589](https://intel.threadlinqs.com/cve/CVE-2026-96589) — CVSS 4.3 medium · EPSS 0.2% · published 2026-10-06
- [CVE-2026-55250](https://intel.threadlinqs.com/cve/CVE-2026-55250) — EPSS 0.5% · published 2026-09-08

## Affected vendors

- [Gitea](https://intel.threadlinqs.com/vendors/gitea) — 1 CVE
- [Linux](https://intel.threadlinqs.com/vendors/linux) — 1 CVE
- **Sylius** — 1 CVE
- **macropay-solutions** — 1 CVE

## Threat activity

7 tracked threats cite CWE-672:

- [Gitea 28.x Patches 27 Security Flaws Including Critical SSH Public-Key Authentication Bypass (CVE-2026-103059), SSRF/DNS Rebinding and Actions Approval Bypasses](https://intel.threadlinqs.com/threat/TL-2026-3046) — CRITICAL · 2026-10-08
- [Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)](https://intel.threadlinqs.com/threat/TL-2026-1807) — HIGH · 2026-08-01
- [LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)](https://intel.threadlinqs.com/threat/TL-2026-0926) — MEDIUM · 2026-06-24
- [Klue OAuth Supply-Chain Breach Enables 'Icarus' Salesforce CRM Data-Theft Extortion Campaign](https://intel.threadlinqs.com/threat/TL-2026-0853) — HIGH · 2026-06-18
- [CVE-2026-23111: Linux Kernel nf_tables Use-After-Free Enables Local Privilege Escalation and Container Escape](https://intel.threadlinqs.com/threat/TL-2026-0731) — HIGH · 2026-06-09
- [PinTheft — Linux Kernel RDS Zerocopy FOLL_PIN Refcount Imbalance Chained With io_uring Fixed Buffers For Page-Cache Overwrite And Local Root (Public PoC, Arch Linux Default-Affected)](https://intel.threadlinqs.com/threat/TL-2026-0543) — HIGH · 2026-05-21
- [Dead.Letter — CVE-2026-45185 Unauthenticated Pre-Auth RCE in Exim via Use-After-Free in BDAT/GnuTLS](https://intel.threadlinqs.com/threat/TL-2026-0513) — CRITICAL · 2026-05-13

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-666](https://cwe.mitre.org/data/definitions/666.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-672
Source definition: https://cwe.mitre.org/data/definitions/672.html
Detection rules and IOCs for threats exploiting CWE-672 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
