CWE-617— Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.— MITRE CWE catalog
878 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-617page 8 of 18
- CVE-2019-6476HIGHCVSS 5.9EG 7.52019-10-17
A defect in code added to support QNAME minimization can cause named to exit with an assertion failure if a forwarder returns a referral rather than resolving the query. This affects BIND versions 9.14.0 up to 9.14.6, and 9.15.0 up to 9.15…
- CVE-2018-5737HIGHCVSS 5.9EG 7.52019-01-16
A problem with the implementation of the new serve-stale feature in BIND 9.12 can lead to an assertion failure in rbtdb.c, even when stale-answer-enable is off. Additionally, problematic interaction between the serve-stale feature and NSEC…
- CVE-2025-56361HIGHCVSS 5.7EG 7.52026-07-14
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) 1.3 thru 1.4, specifically within the Level Control cluster's server tick logic (`emberAfLevelControlClusterServerTickCallback`). When a MoveToLevel command is …
- CVE-2025-56362HIGHCVSS 5.7EG 7.52026-07-14
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.2, specifically within the Level Control cluster's periodic server tick logic. When a MoveToLevel command is sent and immediately followed by a write…
- CVE-2025-56365HIGHCVSS 5.7EG 7.52026-07-14
A reachable assertion vulnerability exists in the Matter SDK (connectedhomeip) before 1.4.0, in the interaction model command processing logic. When an InvokeCommandRequest is sent to a nonexistent endpoint and cluster (e.g., 0x34), the co…
- CVE-2022-31651HIGHCVSS 5.5EG 7.52022-05-25
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
- CVE-2025-66443HIGHCVSS 5.3EG 7.52025-12-25
Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improper Input Validation in signalling that allows an attacker to trigger a software abort, resulting in a temporary denial …
- CVE-2017-7539HIGHCVSS 5.3EG 7.52018-07-26
An assertion-failure flaw was found in Qemu before 2.10.1, in the Network Block Device (NBD) server's initial connection negotiation, where the I/O coroutine was undefined. This could crash the qemu-nbd server if a client sent unexpected d…
- CVE-2021-28543HIGHCVSS 4.0EG 7.52021-03-16
Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to in…
- CVE-2023-37013HIGHCVSS 7.3EG 7.32025-01-22
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a sufficiently large ASN.1 packet over the S1AP interface. An attacker may repeatedly send such an oversized packet to cause the `ogs_sctp_recvmsg` rout…
- CVE-2026-53532HIGHCVSS 7.1EG 7.12026-08-24
OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in …
- CVE-2026-63806HIGHCVSS 7.1EG 7.12026-07-19
In the Linux kernel, the following vulnerability has been resolved: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() Drop a BUG_ON() that has been reachable since it was first added, way back in 2009, a…
- CVE-2026-23555HIGHCVSS 7.1EG 7.12026-03-23
Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error indicator in xenstored when verifying the node path. Note that the crash is forced via a f…
- CVE-2025-4321HIGHCVSS 7.1EG 7.12025-11-17
In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard reset will bring the device to normal operation
- CVE-2021-35101HIGHCVSS 7.1EG 7.12022-06-14
Improper handling of writes to virtual GICR control can lead to assertion failure in the hypervisor in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile
- CVE-2023-28425HIGHCVSS 5.5EG 7.12023-03-20
Redis is an in-memory database that persists on disk. Starting in version 7.0.8 and prior to version 7.0.10, authenticated users can use the MSETNX command to trigger a runtime assertion and termination of the Redis server process. The pro…
- CVE-2026-29115MEDIUMCVSS 6.9EG 6.92026-06-10
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service.
- CVE-2026-102916MEDIUMCVSS 6.8EG 6.82026-10-09
A reachable assertion in the illumos bhyve instruction emulator allows a guest to panic the host. When emulating a REP-prefixed MOVS or STOS instruction that accesses guest MMIO, vie_emulate_movs() and vie_emulate_stos() in usr/src/uts/int…
- CVE-2021-1440MEDIUMCVSS 6.8EG 6.82024-11-18
A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resul…
- CVE-2022-20694MEDIUMCVSS 6.8EG 6.82022-04-15
A vulnerability in the implementation of the Resource Public Key Infrastructure (RPKI) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Border Gateway Protocol (BGP) process to crash, resulting …
- CVE-2026-19395MEDIUMCVSS 6.6EG 6.62026-10-05
In Qt for MCUs, a Text element that displays styled text halts the device if an <img> tag in the text contains an attribute with an empty value. The text parser passes the empty value to an internal check that only accepts non-empty values…
- CVE-2026-105754MEDIUMCVSS 6.5EG 6.52026-10-05
vLLM is an inference and serving engine for large language models. Prior to 0.30.0, the /inference/v1/generate endpoint in the disaggregated scale-out path accepts caller-supplied tensors in the features.kwargs_data field, cache identifier…
- CVE-2026-105753MEDIUMCVSS 6.5EG 6.52026-10-05
vLLM is an inference and serving engine for large language models. Prior to 0.28.0, the default mirrored multimodal LRU cache can commit a media hash in the frontend sender cache during multimodal rendering and before engine admission, whi…
- CVE-2026-104434MEDIUMCVSS 6.5EG 6.52026-10-02
ZcashFoundation Zebra zebra-rpc before 8.0.0 and zebrad before 4.5.0 contain a reachable assertion in the z_listunifiedreceivers RPC handler, which calls expect() on Sapling receiver parsing that fails for Unified Addresses carrying invali…
- CVE-2026-91961MEDIUMCVSS 6.5EG 6.52026-09-15
FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfe…
- CVE-2026-91951MEDIUMCVSS 6.5EG 6.52026-09-15
FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigge…
- CVE-2026-15893MEDIUMCVSS 6.5EG 6.52026-09-14
net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reachable_time as min_reachable + sys_rand32_get() % (max_reachable - min_reachable), where min_reachable = base/2 and max_r…
- CVE-2026-82068MEDIUMCVSS 6.5EG 6.52026-09-08
A security issue in MongoDB Server allows an authenticated user with write privileges to trigger a persistent fatal assertion crash by sending specially crafted retryable write commands. The crash state is durably persisted, causing the se…
- CVE-2026-82065MEDIUMCVSS 6.5EG 6.52026-09-08
A security issue in the MongoDB Server's storage engine integration layer allows an authenticated user with collection creation privileges to cause a persistent denial of service. Insufficient validation of user-supplied storage configurat…
- CVE-2026-82059MEDIUMCVSS 6.5EG 6.52026-09-08
An internal aggregation expression in MongoDB Server was incorrectly registered as accessible to any authenticated user rather than being restricted to internal cluster operations. By crafting a malformed index specification within this ex…
- CVE-2026-82052MEDIUMCVSS 6.5EG 6.52026-09-08
The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a MongoDB server (mongod). Under certain specific conditions the regex match can start in the middle of a multi-code-unit …
- CVE-2026-79379MEDIUMCVSS 6.5EG 6.52026-09-08
A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x and earlier and fixed in v.5.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted frame.
- CVE-2026-84971MEDIUMCVSS 6.5EG 6.52026-09-03
Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using the library. A party able to place a suitably formed encrypted val…
- CVE-2026-76926MEDIUMCVSS 6.5EG 6.52026-08-19
BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-43667MEDIUMCVSS 6.5EG 6.52026-08-17
A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS 26.5, watchOS 26.5. An attacker in a privileged network positio…
- CVE-2026-18695MEDIUMCVSS 6.5EG 6.52026-08-11
An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could allow an authenticated user with write access to cause the server process to terminate unexpectedly, resulting in a de…
- CVE-2026-13055MEDIUMCVSS 6.5EG 6.52026-07-22
The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod). The expression fails to handle compound wildcard index specifications, triggering an internal consistency check that …
- CVE-2026-13058MEDIUMCVSS 6.5EG 6.52026-07-22
An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a crafted transaction command with an incomplete set of required fields. The issue stems from inconsistent validation across …
- CVE-2026-9737MEDIUMCVSS 6.5EG 6.52026-07-22
During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect transformations leading to invariant failure.
- CVE-2026-10822MEDIUMCVSS 6.5EG 6.52026-07-22
If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND will first need to store a DNS record for a key (KEY, DNSKEY, etc.). That key must specify …
- CVE-2026-63140MEDIUMCVSS 6.5EG 6.52026-07-21
Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted search request containing a null value in a specific query clause causes an internal assertion to be …
- CVE-2026-55514MEDIUMCVSS 6.5EG 6.52026-07-06
vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a /v1/completions request with a model using M-RoPE causes EngineCore to fail an assertion and fatally crash, shutting d…
- CVE-2026-9718MEDIUMCVSS 6.5EG 6.52026-06-25
CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed se…
- CVE-2026-47145MEDIUMCVSS 6.5EG 6.52026-06-25
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster…
- CVE-2026-47146MEDIUMCVSS 6.5EG 6.52026-06-25
In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These messages must come from a device that has already joined the network. Only devices supporting the Color Control cluster…
- CVE-2026-10651MEDIUMCVSS 6.5EG 6.52026-06-22
bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-marker byte plus the 2-byte attribute ID (a check of buf->len < 3) but then read a fourth byte, the data-element descri…
- CVE-2026-55776MEDIUMCVSS 6.5EG 6.52026-06-19
OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with write access to transit/keys/* could terminate the server process by setting derived to true while the type parameter …
- CVE-2026-52718MEDIUMCVSS 6.5EG 6.52026-06-15
A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API that expects a bit count, causing parser desynchroniz…
- CVE-2026-9750MEDIUMCVSS 6.5EG 6.52026-06-09
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from insufficient separation between user-contr…
- CVE-2026-9749MEDIUMCVSS 6.5EG 6.52026-06-09
This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces enough documents to fill its exchange buf…
Map vulnerabilities like CWE-617 to your infrastructure
EchelonGraph correlates every CVE — across CWE-617 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →