CWE-617— Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.— MITRE CWE catalog
878 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-617page 9 of 18
- CVE-2026-9748MEDIUMCVSS 6.5EG 6.52026-06-09
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a general purpose skip mechanism, but rather a TeeBuffer-internal sign…
- CVE-2026-9747MEDIUMCVSS 6.5EG 6.52026-06-09
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
- CVE-2026-9746MEDIUMCVSS 6.5EG 6.52026-06-09
When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special privileges needed. The user must be logged in to issue the statement.
- CVE-2026-35058MEDIUMCVSS 6.5EG 6.52026-06-08
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially …
- CVE-2026-23557MEDIUMCVSS 6.5EG 6.52026-05-19
Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() triggering. In case xenstored was built with NDEBUG #defined nothing bad will happen, as assert() is doing nothing in thi…
- CVE-2026-8843MEDIUMCVSS 6.5EG 6.52026-05-18
Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server. A similar issue occurs when creating "queryabl…
- CVE-2026-41585MEDIUMCVSS 6.5EG 6.52026-05-08
ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1.0.0-beta.45 to before 6.0.2, a vulnerability in Zebra's JSON-RPC HTTP middleware allows an authenticated RPC client to…
- CVE-2026-20450MEDIUMCVSS 6.5EG 6.52026-05-04
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges need…
- CVE-2026-33977MEDIUMCVSS 6.5EG 6.52026-03-30
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can crash the FreeRDP client by sending audio data in IMA ADPCM format with an invalid initial step index value (>= 89). The u…
- CVE-2026-33952MEDIUMCVSS 6.5EG 6.52026-03-30
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length field read from the network triggers a WINPR_ASSERT() failure in rts_read_auth_verifier_no_checks(), causing any FreeRDP c…
- CVE-2026-3119MEDIUMCVSS 6.5EG 6.52026-03-25
Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affected code can only be reached if an incoming request has a valid transaction signature (TSIG) from a key declared in the…
- CVE-2025-69653MEDIUMCVSS 6.5EG 6.52026-03-06
A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbba8a88eaa40d15a8a9b70bb1a0b8fb5b552e6 (2025-12-11), in file gc_decref_child in quickjs.c, when executed with the qjs int…
- CVE-2025-47384MEDIUMCVSS 6.5EG 6.52026-03-02
Transient DOS when MAC configures config id greater than supported maximum value.
- CVE-2025-47371MEDIUMCVSS 6.5EG 6.52026-03-02
Transient DOS when an LTE RLC packet with invalid TB is received by UE.
- CVE-2026-27015MEDIUMCVSS 6.5EG 6.52026-02-25
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align()` (`libfreerdp/utils/smartcard_pack.c:1703`) allows a malicious RDP server to crash the …
- CVE-2025-48023MEDIUMCVSS 6.5EG 6.52026-02-13
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and ve…
- CVE-2025-48020MEDIUMCVSS 6.5EG 6.52026-02-13
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and ve…
- CVE-2025-48019MEDIUMCVSS 6.5EG 6.52026-02-13
A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected product receives maliciously crafted packets, Vnet/IP software stack process may be terminated. The affected products and ve…
- CVE-2026-25610MEDIUMCVSS 6.5EG 6.52026-02-10
An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.
- CVE-2025-12131MEDIUMCVSS 6.5EG 6.52026-02-05
A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
- CVE-2025-68471MEDIUMCVSS 6.5EG 6.52026-01-12
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending 2 unsolicited announcements with CNAME resource records 2 seconds a…
- CVE-2025-68468MEDIUMCVSS 6.5EG 6.52026-01-12
Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2 and earlier, avahi-daemon can be crashed by sending unsolicited announcements containing CNAME resource records pointin…
- CVE-2025-20791MEDIUMCVSS 6.5EG 6.52025-12-02
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges need…
- CVE-2025-20757MEDIUMCVSS 6.5EG 6.52025-12-02
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges nee…
- CVE-2025-20752MEDIUMCVSS 6.5EG 6.52025-12-02
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed…
- CVE-2025-13644MEDIUMCVSS 6.5EG 6.52025-11-25
MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue arises when the server mistakenly assumes the presence of multiple documents in a batch based solely on document size ex…
- CVE-2025-60632MEDIUMCVSS 6.5EG 6.52025-11-24
An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST request to the Npcf_BDTPolicyControl API.
- CVE-2025-47370MEDIUMCVSS 6.5EG 6.52025-11-04
Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan.
- CVE-2025-52964MEDIUMCVSS 6.5EG 6.52025-07-11
A Reachable Assertion vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS). When the device receives a sp…
- CVE-2025-22919MEDIUMCVSS 6.5EG 6.52025-02-18
A reachable assertion in FFmpeg git-master commit N-113007-g8d24a28d06 allows attackers to cause a Denial of Service (DoS) via opening a crafted AAC file.
- CVE-2024-7139MEDIUMCVSS 6.5EG 6.52024-12-19
Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which results in a temporary denial of service. If a watchdog timer is not enabled, a hard reset i…
- CVE-2024-7138MEDIUMCVSS 6.5EG 6.52024-12-19
An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. If a watchdog timer is not enabled, a hard reset is required to recover the device.
- CVE-2024-20139MEDIUMCVSS 6.5EG 6.52024-12-02
In Bluetooth firmware, there is a possible firmware asssert due to improper handling of exceptional conditions. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2024-50615MEDIUMCVSS 6.5EG 6.52024-10-27
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
- CVE-2024-50614MEDIUMCVSS 6.5EG 6.52024-10-27
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
- CVE-2024-50613MEDIUMCVSS 6.5EG 6.52024-10-27
libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.
- CVE-2024-23350MEDIUMCVSS 6.5EG 6.52024-08-05
Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.
- CVE-2022-38349MEDIUMCVSS 6.5EG 6.52023-08-22
An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.
- CVE-2022-37052MEDIUMCVSS 6.5EG 6.52023-08-22
A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.
- CVE-2022-37051MEDIUMCVSS 6.5EG 6.52023-08-22
An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.
- CVE-2021-46179MEDIUMCVSS 6.5EG 6.52023-08-22
Reachable Assertion vulnerability in upx before 4.0.0 allows attackers to cause a denial of service via crafted file passed to the the readx function.
- CVE-2023-37836MEDIUMCVSS 6.5EG 6.52023-07-13
libjpeg commit db33a6e was discovered to contain a reachable assertion via BitMapHook::BitMapHook at bitmaphook.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
- CVE-2022-2520MEDIUMCVSS 6.5EG 6.52022-08-31
A flaw was found in libtiff 4.4.0rc1. There is a sysmalloc assertion fail in rotateImage() at tiffcrop.c:8621 that can cause program crash when reading a crafted input.
- CVE-2022-36522MEDIUMCVSS 6.5EG 6.52022-08-26
Mikrotik RouterOs through stable v6.48.3 was discovered to contain an assertion failure in the component /advanced-tools/nova/bin/netwatch. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted packet.
- CVE-2021-46784MEDIUMCVSS 6.5EG 6.52022-07-17
In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.
- CVE-2021-3430MEDIUMCVSS 6.5EG 6.52022-06-28
Assertion reachable with repeated LL_CONNECTION_PARAM_REQ. Zephyr versions >= v1.14 contain Reachable Assertion (CWE-617). For more information, see https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-46h3-hjcq-2jjr
- CVE-2022-31100MEDIUMCVSS 6.5EG 6.52022-06-27
rulex is a new, portable, regular expression language. When parsing untrusted rulex expressions, rulex may crash, possibly enabling a Denial of Service attack. This happens when the expression contains a multi-byte UTF-8 code point in a st…
- CVE-2022-34000MEDIUMCVSS 6.5EG 6.52022-06-19
libjxl 0.6.1 has an assertion failure in LowMemoryRenderPipeline::Init() in render_pipeline/low_memory_render_pipeline.cc.
- CVE-2022-32978MEDIUMCVSS 6.5EG 6.52022-06-10
There is an assertion failure in SingleComponentLSScan::ParseMCU in singlecomponentlsscan.cpp in libjpeg before 1.64 via an empty JPEG-LS scan.
- CVE-2022-31620MEDIUMCVSS 6.5EG 6.52022-05-25
In libjpeg before 1.64, BitStream<false>::Get in bitstream.hpp has an assertion failure that may cause denial of service. This is related to out-of-bounds array access during arithmetically coded lossless scan or arithmetically coded seque…
Map vulnerabilities like CWE-617 to your infrastructure
EchelonGraph correlates every CVE — across CWE-617 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →