CWE-402: Transmission of Private Resources into a New Sphere ('Resource Leak')
Also known as: Resource Leak
The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.
Last updated
Overview
CWE-402 (Transmission of Private Resources into a New Sphere ('Resource Leak')) is a class-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
22 recorded CVEs are caused by CWE-402 (Transmission of Private Resources into a New Sphere ('Resource Leak')). The highest-severity and most recent are shown first. 0 new CWE-402 CVEs have been recorded so far in 2026 (9 in 2025).