CWE-617: Reachable Assertion — known CVE vulnerabilities
CVEs classified under CWE-617 (Reachable Assertion), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2024-35884 — CVSS 9.8 (critical): In the Linux kernel, the following vulnerability has been resolved: udp: do not accept non-tunnel GSO skbs landing in a tunnel When…
CVE-2020-3615 — CVSS 9.8 (critical): Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to…
CVE-2019-9795 — CVSS 9.8 (critical): A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to…
CVE-2026-52952 — CVSS 8.8 (high): In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset In…
CVE-2026-31739 — CVSS 8.8 (high): In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - Add missing CRYPTO_ALG_ASYNC The tegra crypto driver…
CVE-2020-12417 — CVSS 8.8 (high): Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a…
CVE-2026-29116: A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet…
CVE-2025-34458: wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the…
CVE-2024-24429 — CVSS 8.6 (high): A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a…
CVE-2024-34235 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37023 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contain a reachable assertion in the `Uplink NAS Transport` packet handler. A packet missing its…
CVE-2023-37021 — CVSS 8.6 (high): Open5GS MME version <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37020 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37019 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37018 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37017 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37016 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-37015 — CVSS 8.6 (high): Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An…
CVE-2023-49286 — CVSS 8.6 (high): Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is…
CVE-2026-63388 — CVSS 8.4 (high): Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c…
CVE-2021-30335 — CVSS 8.4 (high): Possible assertion in QOS request due to improper validation when multiple add or update request are received simultaneously in Snapdragon…
CVE-2026-46117 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()…
CVE-2026-31398 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: mm/rmap: fix incorrect pte restoration for lazyfree folios We batch…
CVE-2023-53683 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: fs: hfsplus: remove WARN_ON() from hfsplus_cat_{read,write}_inode()…
CVE-2025-39803 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Remove WARN_ON_ONCE() call from ufshcd_uic_cmd_compl()…
CVE-2022-49154 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: fix panic on out-of-bounds guest IRQ As guest_irq is coming…
CVE-2021-47351 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: ubifs: Fix races between xattr_{set|get} and listxattr operations UBIFS…
CVE-2023-52621 — CVSS 7.8 (high): In the Linux kernel, the following vulnerability has been resolved: bpf: Check rcu_read_lock_trace_held() before calling bpf map helpers…
CVE-2024-25445 — CVSS 7.8 (high): Improper handling of values in HuginBase::PTools::Transform::transform of Hugin 2022.0.0 leads to an assertion failure.
CVE-2021-36409 — CVSS 7.8 (high): There is an Assertion `scaling_list_pred_matrix_id_delta==1' failed at sps.cc:925 in libde265 v1.0.8 when decoding file, which allows…
CVE-2019-14049 — CVSS 7.8 (high): Stage-2 fault will occur while writing to an ION system allocation which has been assigned to non-HLOS memory which is non-standard in…
CVE-2018-19963 — CVSS 7.8 (high): An issue was discovered in Xen 4.11 allowing HVM guest OS users to cause a denial of service (host OS crash) or possibly gain host OS…
CVE-2017-7605 — CVSS 7.8 (high): aacplusenc.c in HE-AAC+ Codec (aka libaacplus) 2.0.2 has an assertion failure, which might allow remote attackers to cause a denial of…
CVE-2026-41485 — CVSS 7.7 (high): Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to versions 1.17.2 and 1.16.4, an unchecked type…
CVE-2021-1422 — CVSS 7.7 (high): A vulnerability in the software cryptography module of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense…
CVE-2026-103108 — CVSS 7.5 (high): Pexip Infinity before 38.2, plus 39.0, 39.1, and 40.0, is affected by improper input validation in the media implementation that allows a…
CVE-2026-103104 — CVSS 7.5 (high): Pexip Infinity before 38.2, plus 39.0, 39.1 and 40.0, is affected by improper input validation in the media implementation which allows a…
CVE-2026-103100 — CVSS 7.5 (high): Pexip Infinity before 40.1 is affected by improper input validation in the signaling implementation that allows a malicious attacker to…
CVE-2026-103099 — CVSS 7.5 (high): Pexip Infinity before 41.1 is affected by improper input validation in the media implementation that allows a remote attacker to trigger a…
CVE-2026-94623 — CVSS 7.5 (high): vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly…
CVE-2026-75894 — CVSS 7.5 (high): In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found in the ranap_handle_co_dt() function via a arbitrarily sized NAS-PDU…
CVE-2026-92971 — CVSS 7.5 (high): InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows…
CVE-2026-80274 — CVSS 7.5 (high): If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer…
CVE-2026-76163 — CVSS 7.5 (high): If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which…
CVE-2026-75584 — CVSS 7.5 (high): ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process…
CVE-2026-82064 — CVSS 7.5 (high): A security issue in MongoDB Server allows an unauthenticated network user to cause a denial of service on a specific type of replica set…