CWE-617: Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
325 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-24826 — Out-of-bounds write in turso3d
- CVE-2025-34458 — wb2osz/direwolf <= 1.8.1 Reachable Assertion DoS
- CVE-2025-41068 — Reachable Assertion vulnerability in Open5GS
- CVE-2025-41067 — Reachable Assertion vulnerability in Open5GS
- CVE-2024-39697 — phonenumber panics on parsing crafted phonenumber inputs
- CVE-2026-34219 — libp2p-gossipsub: Gossipsub PRUNE Backoff Heartbeat Instant Overflow
- CVE-2026-63140 — Reachable Assertion in Elasticsearch Leading to Denial of Service
- CVE-2026-41584 — ZEBRA: rk Identity Point Panic in Transaction Verification
- CVE-2024-47522 — Suricata ja4: invalid alpn leads to panic
- CVE-2025-66443 — Pexip Infinity 35.0 through 38.1 before 39.0, in non-default configurations that use Direct Media for WebRTC, has Improp
- CVE-2025-66379 — Pexip Infinity before 39.0 has Improper Input Validation in the media implementation, allowing a remote attacker to trig
- CVE-2025-59530 — quic-go has Client Crash Due to Premature HANDSHAKE_DONE Frame
- CVE-2025-48704 — Pexip Infinity 35.0 through 37.2 before 38.0 has Improper Input Validation in signalling that allows an attacker to trig
- CVE-2025-46705 — A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.
- CVE-2025-46354 — A denial of service vulnerability exists in the Distributed Transaction Commit/Abort Operation functionality of Bloomber
- CVE-2025-40777 — A possible assertion failure when 'stale-answer-client-timeout' is set to '0'
- CVE-2025-36512 — A denial of service vulnerability exists in the Bloomberg Comdb2 8.1 database when handling a distributed transaction he
- CVE-2025-32096 — Pexip Infinity 33.0 through 37.0 before 37.1 has improper input validation in signaling that allows an attacker to trigg
- CVE-2025-32095 — Pexip Infinity before 37.0 has improper input validation in signalling that allows a remote attacker to trigger a softwa
- CVE-2025-27073 — Reachable Assertion in WLAN Firmware
Recently published
- CVE-2026-82068 — Persistent Fatal Assertion Crash in MongoDB Server via Crafted Retryable Write Commands Leads to Denial of Service
- CVE-2026-82065 — Insufficient Validation of Storage Configuration Options in MongoDB Server Leads to Persistent Denial of Service via Corrupted Metadata
- CVE-2026-82064 — Unauthenticated Denial of Service in MongoDB Server via Assertion Failure in Read Concern Processing on Replica Set Members
- CVE-2026-82059 — Improper Access Restriction of Internal Aggregation Expression in MongoDB Server Leads to Assertion Failure and Denial of Service
- CVE-2026-82052 — $regexFindAll may crash mongod server when byte-matching multi-byte UTF-8 chars
- CVE-2026-86317 — ggml-org llama.cpp RPC Server ggml-rpc.cpp deserialize_tensor assertion
- CVE-2026-20504 — In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i
- CVE-2026-20503 — In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i
- CVE-2026-31911 — abort() in libpcap before 1.10.7 on an invalid BPF opcode
- CVE-2026-85534 — Libsoup: libsoup: http/2 client crash in on_data_source_read_callback when settings initial_window_size shrinks during deferred body read
- CVE-2026-84971 — Persistent client crash loop via undersized FLE2 insert-update ciphertext in decryption path
- CVE-2026-14957 — FIPS mode assertion failure via malicious CERT payload
- CVE-2026-82590 — Open5GS SMF nudm-handler.c smf_nudm_sdm_handle_get assertion
- CVE-2026-19401 — Remote UDP DoS by sending multiple DNS Cookie options
- CVE-2026-53532 — OpenEXR: Unhandled assert abort in HTJ2K decoder via crafted QCD marker (DoS)
- CVE-2026-78186 — Open5GS HSS hss-cx-path.c assertion
- CVE-2026-63388 — Libevent: Heap out-of-bounds write in bufferevent_socket_set_conn_address_ reachable via AF_UNIX accept
- CVE-2026-76926 — Reachable Assertion in Wireshark
- CVE-2026-62377 — libheif: Reachable assertion in HeifContext::get_track() aborts on a valid-but-empty HEIF sequence file (context.cc:2110)
- CVE-2026-52829 — ZEBRA: IPv4-Mapped Mempool Misbehavior Update Aborts Zebra Address Book