CWE-617

Reachable Assertion

Parent: CWE-705 - Incorrect Control Flow Scoping

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

794 vulnerabilities with CWE-617
CVE-2026-37229 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via Malformed ASN.1 PER Decoding
CVSS 7.5
CVE-2026-37228 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via SCTP Message Overflow
CVSS 7.5
CVE-2026-37227 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via E2AP PDU Message Handling
CVSS 7.5
CVE-2026-37225 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via Empty ricEventTriggerDefinition Field
CVSS 7.5
CVE-2026-37224 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via Duplicate E2_SETUP_REQUEST
CVSS 7.5
CVE-2026-37223 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via E2AP Message Type Whitelist Bypass
CVSS 7.5
CVE-2026-37222 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via E2AP Message IE Count Assertion
CVSS 7.5
CVE-2026-37221 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via Forged RIC_SUBSCRIPTION_RESPONSE
CVSS 7.5
CVE-2026-37220 HIGH
FlexRIC 2.0.0 - Unauthenticated Denial of Service via SCTP Association Teardown
CVSS 7.5
CVE-2026-46220 MEDIUM
drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
CVSS 5.5
CVE-2026-46117 HIGH
RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()
CVSS 7.8
CVE-2026-4392 MEDIUM
TeamSpeak 3 Server clientek Handshake assertion
CVSS 5.3
CVE-2026-44321 HIGH
free5GC: SMF UPI POST /upi/v1/upNodesLinks exits the SMF process on overlapping UE pools (unauthenticated, reachable Fatalf)
CVSS 7.5
CVE-2026-44319 HIGH
free5GC: NEF crashes via logger.Fatal on PFD notification delivery failure (attacker-controlled notifyUri)
CVSS 7.5
CVE-2026-45847 MEDIUM
net: remove WARN_ON_ONCE when accessing forward path array
CVSS 5.5
CVE-2026-8852 MEDIUM
IBM HTTP Server is affected by multiple vulnerabilities
CVSS 6.2
CVE-2026-9501 LOW
GNU LibreDWG Dwgread Utility decode.c decompress_R2004_section assertion
CVSS 3.3
CVE-2026-48852 LOW
PuTTY < 0.84 - Reachable Assertion
CVSS 3.7
CVE-2026-5946 HIGH
BIND 9.11.0-9.16.50, 9.18.0-9.18.48, 9.20.0-9.20.22, 9.21.0-9.21.21 - DoS via Non-IN DNS Message Handling
CVSS 7.5
CVE-2026-23557 MEDIUM
Xenstored DoS via XS_RESET_WATCHES command
CVSS 6.5
CVE-2026-8843 MEDIUM
Calling createIndex with certain index types can crash mongod
CVSS 6.5
CVE-2026-8257 LOW
WebAssembly Binaryen BrOn wasm-ir-builder.cpp makeBrOn assertion
CVSS 3.3
CVE-2026-41585 MEDIUM
ZEBRA: Denial of Service via Interrupted JSON-RPC Requests from Authenticated Clients
CVSS 6.5
CVE-2026-41584 HIGH
ZEBRA: rk Identity Point Panic in Transaction Verification
CVSS 7.5
CVE-2026-43346 MEDIUM
ice: ptp: don't WARN when controlling PF is unavailable
CVSS 5.5
Details
Vulnerabilities 794