CWE-617

Reachable Assertion

Parent: CWE-705 - Incorrect Control Flow Scoping

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

748 vulnerabilities with CWE-617
CVE-2026-44319 HIGH
free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)
CVSS 7.5
CVE-2026-8852 MEDIUM
IBM HTTP Server is affected by multiple vulnerabilities
CVSS 6.2
CVE-2026-9501 LOW
GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion
CVSS 3.3
CVE-2026-48852 LOW
PuTTY < 0.84 - Reachable Assertion
CVSS 3.7
CVE-2026-5946 HIGH
BIND 9.11.0-9.16.50, 9.18.0-9.18.48, 9.20.0-9.20.22, 9.21.0-9.21.21 - DoS via Non-IN DNS Message Handling
CVSS 7.5
CVE-2026-23557 MEDIUM
Xenstored DoS via XS_RESET_WATCHES command
CVSS 6.5
CVE-2026-8843 MEDIUM
Calling createIndex with certain index types can crash mongod
CVSS 6.5
CVE-2026-8257 LOW
WebAssembly Binaryen BrOn wasm-ir-builder.cpp makeBrOn assertion
CVSS 3.3
CVE-2026-41585 MEDIUM
ZEBRA: Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients
CVSS 6.5
CVE-2026-41584 HIGH
ZEBRA: rk Identity Point Panic in Transaction Verification
CVSS 7.5
CVE-2026-43346 MEDIUM
ice: ptp: don't WARN when controlling PF is unavailable
CVSS 5.5
CVE-2026-43344 MEDIUM
perf/x86/intel/uncore: Fix die ID init and look up bugs
CVSS 5.5
CVE-2026-43228 MEDIUM
hfs: Replace BUG_ON with error handling for CNID count checks
CVSS 5.5
CVE-2026-20450 MEDIUM
MediaTek chipset - Remote Denial of Service via Rogue Base Station
CVSS 6.5
CVE-2026-43046 MEDIUM
btrfs: reject root items with drop_progress and zero drop_level
CVSS 5.5
CVE-2026-31739 HIGH
crypto: tegra - Add missing CRYPTO_ALG_ASYNC
CVSS 8.8
CVE-2026-31567 MEDIUM
PM: sleep: Drop spurious WARN_ON() from pm_restore_gfp_mask()
CVSS 5.5
CVE-2026-41485 HIGH
Kyverno Controller Denial of Service via forEach Mutation Panic
CVSS 7.7
CVE-2026-34067 LOW
nimiq-transaction vulnerable to panic via `HistoryTreeProof` length mismatch
CVSS 3.1
CVE-2026-34066 MEDIUM
nimiq-blockchain: Peer-triggerable panic during history sync
CVSS 5.3
CVE-2026-34063 HIGH
network-libp2p: Peer can crash the node by opening discovery protocol substream twice
CVSS 7.5
CVE-2026-31451 MEDIUM
ext4: replace BUG_ON with proper error handling in ext4_read_inline_folio
CVSS 5.5
CVE-2026-34069 MEDIUM
nimiq-consensus panics via RequestMacroChain micro-block locator
CVSS 5.3
CVE-2026-31415 MEDIUM
ipv6: avoid overflows in ip6_datagram_send_ctl()
CVSS 5.5
CVE-2026-34933 MEDIUM
Avahi: Reachable assertion in `transport_flags_from_domain()` via conflicting publish flags crashes avahi-daemon
CVSS 5.5
Details
Vulnerabilities 748