CWE-617

Reachable Assertion

Parent: CWE-705 - Incorrect Control Flow Scoping

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

748 vulnerabilities with CWE-617
CVE-2026-22990 HIGH
Linux Kernel - Reachable Assertion in libceph osdmap_apply_incremental
CVSS 7.5
CVE-2026-23991 MEDIUM
go-tuf 2.0.0-2.3.0 - Denial of Service via Invalid TUF Metadata JSON
CVSS 5.9
CVE-2025-56568 HIGH
Open5GS < 2.7.5 - Denial of Service via Malformed NGAP Message Length Field
CVSS 7.5
CVE-2025-69653 MEDIUM
QuickJS 2025-09-13 - Denial of Service via Crafted JavaScript Input in Garbage Collection
CVSS 6.5
CVE-2025-47384 MEDIUM
Qualcomm Firmware MAC Config - Denial of Service
CVSS 6.5
CVE-2025-47371 MEDIUM
Qualcomm 5G Fixed Wireless Access Platform Firmware - Denial of Service via Invalid LTE RLC Packet
CVSS 6.5
CVE-2025-48023 MEDIUM
Yokogawa Electric Corporation - DoS
CVSS 6.5
CVE-2025-48020 MEDIUM
Yokogawa Electric Corporation - DoS
CVSS 6.5
CVE-2025-48019 MEDIUM
Yokogawa Electric Corporation - DoS
CVSS 6.5
CVE-2025-12131 MEDIUM
Silabs Simplicity Software Development Kit < 2025.6.2 - Denial of Service via Truncated 802.15.4 Packet
CVSS 6.5
CVE-2025-15497 LOW
OpenVPN 2.7_alpha1-2.7_rc5 - Authenticated Denial of Service via Epoch Key Slot Processing
CVE-2025-13878 HIGH
BIND <9.18.44-9.20.18-9.21.17 - DoS
CVSS 7.5
CVE-2025-61684 HIGH
Quicly < 2026-01-18 - Denial of Service via Reachable Assertion
CVSS 7.5
CVE-2025-15531 MEDIUM
open5gs < 2.7.5 - Reachable Assertion in sgwc_bearer_add Function
CVSS 5.3
CVE-2025-15530 MEDIUM
open5gs < 2.7.6 - Reachable Assertion in sgwc_s11_handle_create_indirect_data_forwarding_tunnel_request
CVSS 5.3
CVE-2025-71085 MEDIUM
Linux Kernel 4.8.0-6.18.4 - Reachable Assertion via Negative Headroom in calipso_skbuff_setattr()
CVSS 5.5
CVE-2025-71080 MEDIUM
Linux Kernel - Reachable Assertion in rt6_make_pcpu_route()
CVSS 5.5
CVE-2025-68471 MEDIUM
avahi < 0.9 - Denial of Service via CNAME Resource Record Announcements
CVSS 6.5
CVE-2025-68468 MEDIUM
avahi < 0.9 - Denial of Service via CNAME Resource Record Expiration
CVSS 6.5
CVE-2025-68276 MEDIUM
avahi < 0.9 - Denial of Service via D-Bus Record Browser Creation
CVSS 5.5
CVE-2025-20762 MEDIUM
MediaTek NR17 - Remote Denial of Service via Rogue Base Station
CVSS 6.5
CVE-2025-20760 MEDIUM
Mediatek Nr15 - Reachable Assertion
CVSS 6.5
CVE-2025-15176 MEDIUM
open5gs < 2.7.5 - Reachable Assertion in PFCP Session Establishment Request Handler
CVSS 5.3
CVE-2025-66443 HIGH
Pexip Infinity 35.0-38.1 - Denial of Service via Direct Media WebRTC Signalling
CVSS 7.5
CVE-2025-66379 HIGH
Pexip Infinity < 39.0 - Denial of Service via Crafted Media Stream
CVSS 7.5
Details
Vulnerabilities 748