CWE-617— Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.— MITRE CWE catalog
878 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-617page 3 of 18
- CVE-2026-27135HIGHCVSS 7.5EG 7.52026-03-18
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_sessio…
- CVE-2025-69534HIGHCVSS 7.5EG 7.52026-03-05
Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, a…
- CVE-2026-27623HIGHCVSS 7.5EG 7.52026-02-23
Valkey is a distributed key-value database. Starting in version 9.0.0 and prior to version 9.0.3, a malicious actor with network access to Valkey can cause the system to abort by triggering an assertion. When processing incoming requests, …
- CVE-2026-2523HIGHCVSS 7.5EG 7.52026-02-16
A vulnerability was detected in Open5GS up to 2.7.6. The affected element is the function smf_gn_handle_create_pdp_context_request of the file /src/smf/gn-handler.c of the component SMF. The manipulation results in reachable assertion. It …
- CVE-2026-20401HIGHCVSS 7.5EG 7.52026-02-02
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed.…
- CVE-2026-23991HIGHCVSS 7.5EG 7.52026-01-22
go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata…
- CVE-2025-13878HIGHCVSS 7.5EG 7.52026-01-21
Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.…
- CVE-2025-61684HIGHCVSS 7.5EG 7.52026-01-19
Quicly, an IETF QUIC protocol implementation, is susceptible to a denial-of-service attack prior to commit d9d3df6a8530a102b57d840e39b0311ce5c9e14e. A remote attacker can exploit these bugs to trigger an assertion failure that crashes proc…
- CVE-2025-15530HIGHCVSS 7.5EG 7.52026-01-17
A vulnerability was determined in Open5GS up to 2.7.6. This affects the function sgwc_s11_handle_create_indirect_data_forwarding_tunnel_request of the file /src/sgwc/s11-handler.c. Executing a manipulation can lead to reachable assertion. …
- CVE-2025-15176HIGHCVSS 7.5EG 7.52025-12-29
A flaw has been found in Open5GS up to 2.7.5. This affects the function decode_ipv6_header/ogs_pfcp_pdr_rule_find_by_packet of the file lib/pfcp/rule-match.c of the component PFCP Session Establishment Request Handler. Executing a manipula…
- CVE-2025-66379HIGHCVSS 7.5EG 7.52025-12-25
Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trigger a software abort via a crafted media stream, resulting in a denial of service.
- CVE-2025-48704HIGHCVSS 7.5EG 7.52025-12-25
Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a denial of service.
- CVE-2025-32096HIGHCVSS 7.5EG 7.52025-12-25
Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigger a software abort, resulting in a denial of service.
- CVE-2025-32095HIGHCVSS 7.5EG 7.52025-12-25
Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a software abort via a crafted signalling message, resulting in a denial of service.
- CVE-2025-65559HIGHCVSS 7.5EG 7.52025-12-18
An issue was discovered in Open5GS 2.7.5-49-g465e90f, when processing a PFCP Session Establishment Request (type=50), the UPF crashes with a reachable assertion in `lib/pfcp/context.c` (`ogs_pfcp_object_teid_hash_set`) if the CreatePDR?PDI…
- CVE-2025-47913HIGHCVSS 7.5EG 7.52025-11-13
SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.
- CVE-2025-41068HIGHCVSS 7.5EG 7.52025-10-27
Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. This is achieved by sending the creation of an NF with an invalid type via SBI and then requesting…
- CVE-2025-41067HIGHCVSS 7.5EG 7.52025-10-27
Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause a denial of service. An SBI request that deletes the NRF's own registry causes a check that ends up crashing the NRF pr…
- CVE-2025-59530HIGHCVSS 7.5EG 7.52025-10-10
quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving or malicious server can cause a denial-of-service (DoS) attack on the quic-go client by triggering an assertion failure…
- CVE-2025-8804HIGHCVSS 7.5EG 7.52025-08-10
A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ngap_build_downlink_nas_transport of the component AMF. The manipulation leads to reachable assertion. The attack can be launched remotely. Th…
- CVE-2025-27073HIGHCVSS 7.5EG 7.52025-08-06
Transient DOS while creating NDP instance.
- CVE-2025-27066HIGHCVSS 7.5EG 7.52025-08-06
Transient DOS while processing an ANQP message.
- CVE-2025-21452HIGHCVSS 7.5EG 7.52025-08-06
Transient DOS while processing a random-access response (RAR) with an invalid PDU length on LTE network.
- CVE-2024-42645HIGHCVSS 7.5EG 7.52025-07-29
An issue in FlashMQ v1.14.0 allows attackers to cause an assertion failure via sending a crafted retain message, leading to a Denial of Service (DoS).
- CVE-2024-42644HIGHCVSS 7.5EG 7.52025-07-29
FlashMQ v1.14.0 was discovered to contain an assertion failure in the function PublishCopyFactory::getNewPublish, which occurs when the QoS value of the publish object is greater than 0.
- CVE-2025-46354HIGHCVSS 7.5EG 7.52025-07-22
A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomberg Comdb2 8.1. A specially crafted network packet can lead to a denial of service. An attacker can send a malicious pack…
- CVE-2025-36512HIGHCVSS 7.5EG 7.52025-07-22
A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction heartbeat. A specially crafted protocol buffer message can lead to a denial of service. An attacker can simply connect to…
- CVE-2025-40777HIGHCVSS 7.5EG 7.52025-07-16
If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `disabled`), and if the resolver, in the process of resolving a query, enco…
- CVE-2025-49630HIGHCVSS 7.5EG 7.52025-07-10
In certain proxy configurations, a denial of service attack against Apache HTTP Server versions 2.4.26 through to 2.4.63 can be triggered by untrusted clients causing an assertion in mod_proxy_http2. Configurations affected are a reverse…
- CVE-2025-20666HIGHCVSS 7.5EG 7.52025-05-05
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed.…
- CVE-2025-29339HIGHCVSS 7.5EG 7.52025-04-22
An issue in UPF in Open5GS UPF versions up to v2.7.2 results an assertion failure vulnerability in PFCP session parameter validation. When processing a PFCP Session Establishment Request with PDN Type=0, the UPF fails to handle the invalid…
- CVE-2024-56921HIGHCVSS 7.5EG 7.52025-02-03
An issue was discovered in Open5gs v2.7.2. InitialUEMessage, Registration request sent at a specific time can crash AMF due to incorrect error handling of gmm_state_exception() function upon receipt of the Nausf_UEAuthentication_Authentica…
- CVE-2024-57519HIGHCVSS 7.5EG 7.52025-01-28
An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.
- CVE-2024-24430HIGHCVSS 7.5EG 7.52025-01-22
A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
- CVE-2024-24428HIGHCVSS 7.5EG 7.52025-01-21
A reachable assertion in the oai_nas_5gmm_decode function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.
- CVE-2024-24427HIGHCVSS 7.5EG 7.52025-01-21
A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
- CVE-2024-24420HIGHCVSS 7.5EG 7.52025-01-21
A reachable assertion in the decode_linked_ti_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.
- CVE-2023-37029HIGHCVSS 7.5EG 7.52025-01-21
Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) are susceptible to an assertion-based crash when an oversized NAS packet is received. An attacker may leverage this behavior to repeatedly crash the MM…
- CVE-2023-37024HIGHCVSS 7.5EG 7.52025-01-21
A reachable assertion in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows remote attackers to crash the MME with an unauthenticated cellphone by sending a …
- CVE-2024-8361HIGHCVSS 7.5EG 7.52025-01-07
In SiWx91x devices, the SHA2/224 algorithm returns a hash of 256 bits instead of 224 bits. This incorrect hash length triggers a software assertion, which subsequently causes a Denial of Service (DoS). If a watchdog is implemented, device …
- CVE-2024-53856HIGHCVSS 7.5EG 7.52024-12-05
rPGP is a pure Rust implementation of OpenPGP. Prior to 0.14.1, rPGP allows an attacker to trigger rpgp crashes by providing crafted data. This vulnerability is fixed in 0.14.1.
- CVE-2024-53429HIGHCVSS 7.5EG 7.52024-11-21
Open62541 v1.4.6 is has an assertion failure in fuzz_binary_decode, which leads to a crash.
- CVE-2024-23385HIGHCVSS 7.5EG 7.52024-11-04
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
- CVE-2024-10455HIGHCVSS 7.5EG 7.52024-10-28
Reachable Assertion in BPv7 parser in µD3TN v0.14.0 allows attacker to disrupt service via malformed Extension Block
- CVE-2024-47522HIGHCVSS 7.5EG 7.52024-10-16
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, invalid ALPN in TLS/QUIC traffic when JA4 matching/logging is enabled can lead to Suricata aborti…
- CVE-2024-45795HIGHCVSS 7.5EG 7.52024-10-16
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, rules using datasets with the non-functional / unimplemented "unset" option can trigger an assert…
- CVE-2024-45396HIGHCVSS 7.5EG 7.52024-10-11
Quicly is an IETF QUIC protocol implementation. Quicly up to commtit d720707 is susceptible to a denial-of-service attack. A remote attacker can exploit these bugs to trigger an assertion failure that crashes process using quicly. The vuln…
- CVE-2024-20094HIGHCVSS 7.5EG 7.52024-10-07
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00843282; …
- CVE-2024-8768HIGHCVSS 7.5EG 7.52024-09-17
A flaw was found in the vLLM library. A completions API request with an empty prompt will crash the vLLM API server, resulting in a denial of service.
- CVE-2024-39949HIGHCVSS 7.5EG 7.52024-07-31
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data packets to the interface with vulnerabilities, causing the device to crash.
Map vulnerabilities like CWE-617 to your infrastructure
EchelonGraph correlates every CVE — across CWE-617 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →