Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-617

MITRE ↗

CWE-617

4
CRITICAL
323
HIGH
439
MEDIUM
34
LOW
808 CVEs · Page 2/17
7.5
CVE-2026-30047

A reachable assertion vulnerability in the /nsmf-pdusession/v1/sm-contexts component of Open5GS v2.7.6 allows attackers

7.1
CVE-2026-23555

Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstor

7.1
CVE-2026-10651

bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-

7.1
CVE-2026-63806

In the Linux kernel, the following vulnerability has been resolved: KVM: Replace guest-triggerable BUG_ON() in ioeventf

6.5
CVE-2025-20760

In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote de

6.5
CVE-2025-20762

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,

6.5
CVE-2025-68468

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2

6.5
CVE-2025-68471

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. In 0.9-rc2

6.5
CVE-2026-20405

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, i

6.5
CVE-2026-20422

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service

6.5
CVE-2025-12131

A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.

6.5
CVE-2026-25610

An authorized user may trigger a server crash by running a $geoNear pipeline with certain invalid index hints.

6.5
CVE-2025-48019

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ

6.5
CVE-2025-48020

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ

6.5
CVE-2025-48023

A vulnerability has been found in Vnet/IP Interface Package provided by Yokogawa Electric Corporation. If affected produ

6.5
CVE-2026-27015

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `sma

6.5
CVE-2025-47371

Transient DOS when an LTE RLC packet with invalid TB is received by UE.

6.5
CVE-2025-47384

Transient DOS when MAC configures config id greater than supported maximum value.

6.5
CVE-2025-69653

A crafted JavaScript input can trigger an internal assertion failure in QuickJS release 2025-09-13, fixed in commit 1dbb

6.5
CVE-2026-3119

Under certain conditions, `named` may crash when processing a correctly signed query containing a TKEY record. The affec

6.5
CVE-2026-33952

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length fie

6.5
CVE-2026-33977

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can cra

6.5
CVE-2026-20450

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service,

6.5
CVE-2026-41585

ZEBRA is a Zcash node written entirely in Rust. From zebrad versions 2.2.0 to before 4.3.1 and from zebra-rpc versions 1

6.5
CVE-2026-8843

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to ins

6.5
CVE-2026-23557

Any guest can cause xenstored to crash by issuing a XS_RESET_WATCHES command within a transaction due to an assert() tri

6.5
CVE-2026-35058

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 t

6.5
CVE-2026-9746

When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which

6.5
CVE-2026-9747

Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.

6.5
CVE-2026-9748

The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index st

6.5
CVE-2026-9749

This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-ran

6.5
CVE-2026-9750

An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfe

6.5
CVE-2026-52718

A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse

6.5
CVE-2026-47145

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These

6.5
CVE-2026-47146

In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These

6.5
CVE-2026-9718

CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-servi

6.5
CVE-2026-55514

vLLM is a library for LLM inference and serving. From 0.12.0 to before 0.24.0, sending a pure prompt embeds payload in a

6.5
CVE-2026-63140

Reachable Assertion (CWE-617) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153). A

6.5
CVE-2026-10822

If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequ

6.5
CVE-2026-13055

The `$_internalIndexKey` aggregation expression can be used by any authenticated user to crash a MongoDB server (mongod)

6.5
CVE-2026-13058

An authenticated user with basic write privileges can cause the mongod process to terminate abnormally by sending a craf

6.5
CVE-2026-9737

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the m

6.5
CVE-2026-18695

An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could

6.5
CVE-2026-43667

A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.1

6.2
CVE-2026-8852

IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.

6.2
CVE-2026-47475

NVIDIA TensorRT-LLM contains a vulnerability in the OpenAI-compatible inference API where an attacker could trigger a re

6.2
CVE-2026-71430

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function

6.1
CVE-2026-58307

Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Dat

5.9
CVE-2026-23991

go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if th

5.9
CVE-2026-34219

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to version 0.49.4, the Ru

Frequently Asked Questions

What is CWE-617?

CWE-617 (CWE-617) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-617?

There are 926 CVE records associated with CWE-617 in our database. Of these, 4 are critical severity, 323 are high severity, and 439 are medium severity.

How can I protect against CWE-617 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-617 using AI-powered security agents.

Detect CWE-617 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-617 vulnerabilities across your infrastructure.

Get Started