CWE-617

Reachable Assertion

Parent: CWE-705 - Incorrect Control Flow Scoping

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

794 vulnerabilities with CWE-617
CVE-2026-66754 MEDIUM
Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding
CVSS 5.9
CVE-2026-17574 MEDIUM
NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag
CVE-2026-17513 LOW
ggml-org whisper.cpp ggml.c ggml_ftype_to_ggml_type assertion
CVSS 3.3
CVE-2026-45815 HIGH
Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler
CVSS 7.5
CVE-2026-9737 MEDIUM
Find command with $meta sort can lead to crash
CVSS 6.5
CVE-2026-13073 MEDIUM
MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination
CVSS 4.3
CVE-2026-13058 HIGH
Transaction Command Insufficient Input Validation Leading to Process Termination
CVE-2026-13055 MEDIUM
Server crash via aggregation pipeline expression with compound wildcard index specification
CVSS 6.5
CVE-2026-13204 HIGH
Unexpected exit in certain situations with NSEC and NSEC3 both present
CVSS 7.5
CVE-2026-12617 HIGH
Record ordering based unexpected exit with CNAME or DNAME
CVSS 7.5
CVE-2026-10822 MEDIUM
Key Record using PRIVATEDNS algorithm may lead to unexpected exit
CVSS 6.5
CVE-2026-14586 MEDIUM
Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments
CVSS 5.9
CVE-2026-10674 MEDIUM
DoS (hard fault) in NXP LPUART driver: unsupported runtime UART config leaves clocks disabled
CVSS 5.5
CVE-2026-63140 MEDIUM
Reachable Assertion in Elasticsearch Leading to Denial of Service
CVSS 6.5
CVE-2026-63806 HIGH
KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned()
CVSS 7.1
CVE-2026-44435 HIGH
Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB
CVSS 7.5
CVE-2026-47475 MEDIUM
Nvidia TensorRT-LLM < v1.3.0 rc15 - Reachable Assertion
CVSS 6.2
CVE-2026-58307 MEDIUM
Samsung Open Source Escargot - Out-of-bounds Read
CVSS 6.1
CVE-2026-55514 MEDIUM
vLLM denial of service via prompt embeds on M-RoPE models
CVSS 6.5
CVE-2026-13122 MEDIUM
OpenVPN - Reachable Assertion
CVSS 5.3
CVE-2026-50722 HIGH
IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload
CVSS 8.1
CVE-2026-50721 HIGH
IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload
CVSS 8.1
CVE-2026-12413 HIGH
libreswan - IKEv2 Denial of Service via Malformed Fragmentation
CVSS 7.5
CVE-2026-53319 MEDIUM
blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default()
CVSS 5.5
CVE-2026-53292 MEDIUM
net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind
CVSS 5.5
Details
Vulnerabilities 794