CWE-617

Reachable Assertion

Parent: CWE-705 - Incorrect Control Flow Scoping

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

794 vulnerabilities with CWE-617
CVE-2026-53285 MEDIUM
drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED
CVSS 5.5
CVE-2026-9718 MEDIUM
Schneider Electric PowerLogic™ P7 - Reachable Assertion
CVSS 6.5
CVE-2026-47146 MEDIUM
Color Control color-temperature assertion abort in EmberZNet v9.0.2
CVSS 6.5
CVE-2026-47145 MEDIUM
Color Control hue/saturation assertion abort in EmberZNet v9.0.2
CVSS 6.5
CVE-2026-53169 MEDIUM
accel/ethosu: reject NPU_OP_RESIZE commands from userspace
CVSS 5.5
CVE-2026-53039 MEDIUM
ocfs2: validate group add input before caching
CVSS 5.5
CVE-2026-52961 MEDIUM
ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
CVSS 5.5
CVE-2026-52954 HIGH
libceph: handle rbtree insertion error in decode_choose_args()
CVSS 7.5
CVE-2026-52952 HIGH
iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset
CVSS 8.8
CVE-2026-10651 HIGH
Bluetooth Classic SDP parser truncation bug in bt_sdp_parse_attribute() leads to reachable assertion and possible out-of-bounds read
CVSS 7.1
CVE-2026-41523 HIGH
vLLM < 0.22.0 Activation Function Loading - Unauthenticated Code Execution
CVSS 7.5
CVE-2026-52718 MEDIUM
Gstreamer1-plugins-bad-free: gstreamer: denial of service via av1 tile_list_obu parser byte/bit confusion
CVSS 6.5
CVE-2026-29116 HIGH
Dahua Ipc/sd/nvr/xvr/evs/vto/vth/asi/tpc - Reachable Assertion
CVE-2026-29115 MEDIUM
Dahua Ipc/sd - Reachable Assertion
CVE-2026-46543 MEDIUM
nimiq-blockchain: Genesis batch set request
CVSS 5.3
CVE-2026-46542 MEDIUM
nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points
CVSS 4.3
CVE-2026-9750 MEDIUM
Metadata name collision on $-prefixed fields causes post-auth server crash
CVSS 6.5
CVE-2026-9749 MEDIUM
Using MaxKey() may crash the server
CVSS 6.5
CVE-2026-9748 MEDIUM
$_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries input
CVSS 6.5
CVE-2026-9747 MEDIUM
Crafted cross-shard merge aggregation crashes MongoDB Server
CVSS 6.5
CVE-2026-9746 MEDIUM
Server crashes in case of the use of exchange
CVSS 6.5
CVE-2026-35058 MEDIUM
OpenVPN - Reachable Assertion
CVE-2026-46287 MEDIUM
net: txgbe: fix RTNL assertion warning when remove module
CVSS 5.5
CVE-2026-10300 LOW
SGLang 0.5.10.post1 - Reachable Assertion via lora_path Argument
CVSS 3.7
CVE-2026-37233 HIGH
FlexRIC 2.0.0 - Authorization Bypass via xApp Isolation Mechanism
CVSS 7.5
Details
Vulnerabilities 794