CWE-617

Reachable Assertion

Parent: CWE-705 - Incorrect Control Flow Scoping

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

748 vulnerabilities with CWE-617
CVE-2026-52718 MEDIUM
Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_obu parser byte/bit confusion
CVSS 6.5
CVE-2026-29116 HIGH
Dahua Ipc/sd/nvr/xvr/evs/vto/vth/asi/tpc - Reachable Assertion
CVE-2026-29115 MEDIUM
Dahua Ipc/sd - Reachable Assertion
CVE-2026-46543 MEDIUM
nimiq-blockchain: Genesis batch set request
CVSS 5.3
CVE-2026-46542 MEDIUM
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
CVSS 4.3
CVE-2026-9750 MEDIUM
Metadata name collision on $-prefixed fields causes post-auth server crash
CVSS 6.5
CVE-2026-9749 MEDIUM
Using MaxKey() may crash the server
CVSS 6.5
CVE-2026-9748 MEDIUM
$_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries input
CVSS 6.5
CVE-2026-9747 MEDIUM
Crafted cross-shard merge aggregation crashes MongoDB Server
CVSS 6.5
CVE-2026-9746 MEDIUM
Server crashes in case of the use of exchange
CVSS 6.5
CVE-2026-35058 MEDIUM
OpenVPN - Reachable Assertion
CVE-2026-10300 LOW
SGLang 0.5.10.post1 - Reachable Assertion via lora_path Argument
CVSS 3.7
CVE-2026-37233 HIGH
FlexRIC 2.0.0 - Authorization Bypass via xApp Isolation Mechanism
CVSS 7.5
CVE-2026-37229 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via Malformed ASN.1 PER Decoding
CVSS 7.5
CVE-2026-37228 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via SCTP Message Overflow
CVSS 7.5
CVE-2026-37227 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via E2AP PDU Message Handling
CVSS 7.5
CVE-2026-37225 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via Empty ricEventTriggerDefinition Field
CVSS 7.5
CVE-2026-37224 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via Duplicate E2_SETUP_REQUEST
CVSS 7.5
CVE-2026-37223 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via E2AP Message Type Whitelist Bypass
CVSS 7.5
CVE-2026-37222 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via E2AP Message IE Count Assertion
CVSS 7.5
CVE-2026-37221 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via Forged RIC_SUBSCRIPTION_RESPONSE
CVSS 7.5
CVE-2026-37220 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via SCTP Association Teardown
CVSS 7.5
CVE-2026-46220 MEDIUM
drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
CVSS 5.5
CVE-2026-4392 MEDIUM
TeamSpeak 3 Server clientek Handshake assertion
CVSS 5.3
CVE-2026-44321 HIGH
free5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)
CVSS 7.5
Details
Vulnerabilities 748