Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-617'

View all threats tagged with 'cwe-617'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-617

Threats Tagged 'cwe-617'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-71430: CWE-617: Reachable Assertion in uhop node-re2CVE-2026-71430
0

node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result and passed it to V8 using ToLocalChecked without checking for the empty MaybeLocal that V8 returns when the resulting string or buffer exceeds V8's maximum string length. When a global replace uses an output amplifying replacement template, the result can grow quadratically with the input size, and once the result exceeds V8's maximum string length, the unchecked ToLocalChecked call causes a fatal, uncatchable process abort instead of a catchable exception. This issue is fixed in version 1.25.1.

Join the discussion
CVE-2026-52856: CWE-248: Uncaught Exception in pterodactyl wingsCVE-2026-52856
0

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received during the SFTP connection handshake causes a Go panic. This issue is fixed in version 1.13.0.

Join the discussion
CVE-2026-17574: CWE-617 Reachable assertion in The HDF Group HDF5CVE-2026-17574
0

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.

Join the discussion
CVE-2026-45815: CWE-617 Reachable Assertion in Apache Software Foundation Apache NimBLECVE-2026-45815
0

Reachable Assertion vulnerability in Apache NimBLE. A specially crafted ATT Read Multiple Variable Response (BLE_ATT_OP_READ_MULT_VAR_RSP) may trigger assert in ATT parser. Severity is medium as this requires DUT to first send ATT Read Multiple Variable Request. This issue affects Apache NimBLE: through 1.9.0. Users are recommended to upgrade to version 1.10.0, which fixes the issue.

Join the discussion
CVE-2026-9737: CWE-617 Reachable assertion in MongoDB MongoDB ServerCVE-2026-9737
0

CVE-2026-9737 is a high-severity vulnerability in MongoDB Server involving a reachable assertion failure during query planning. The issue arises when the server reads the sort pattern in raw BSONObj form and does not properly handle the meta expression case, potentially causing an invariant failure. This vulnerability affects specific MongoDB Server versions 7.0, 8.0, 8.2.0, and 8.3.0. No official patch or remediation guidance has been provided yet, and there are no known exploits in the wild.

Join the discussion
CVE-2026-13073: CWE-617: Reachable Assertion in MongoDB MongoDB ServerCVE-2026-13073
0

CVE-2026-13073 is a medium severity vulnerability in MongoDB Server version 8.0 where an authenticated user with read-only privileges can cause the mongod process to crash by issuing a specially crafted aggregation command. This leads to a denial of service affecting all connected clients until the server process is restarted. The root cause is an internal engine selection inconsistency triggered by specific aggregation options.

Join the discussion
CVE-2026-13058: CWE-617: Reachable Assertion in MongoDB MongoDB ServerCVE-2026-13058
0

CVE-2026-13058 is a high-severity vulnerability in MongoDB Server where an authenticated user with basic write privileges can cause the mongod process to crash by sending a crafted transaction command missing required fields. This leads to a denial of service due to an internal assertion failure caused by inconsistent validation of transaction command parameters.

Join the discussion
CVE-2026-13055: CWE-617: Reachable Assertion in MongoDB MongoDB ServerCVE-2026-13055
0

CVE-2026-13055 is a high-severity vulnerability in MongoDB Server affecting versions 7.0, 8.0, 8.2.0, and 8.3.0. It involves the `$_internalIndexKey` aggregation expression, which any authenticated user can use to crash the MongoDB server by triggering an internal assertion failure. This occurs due to improper handling of compound wildcard index specifications during aggregation pipeline execution.

Join the discussion
CVE-2026-13204: CWE-617 Reachable Assertion in ISC BIND 9CVE-2026-13204
0

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof. This issue affects BIND 9 versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Join the discussion
CVE-2026-12617: CWE-617 Reachable Assertion in ISC BIND 9CVE-2026-12617
0

The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Specifically, if a client queries for a DNAME and A record below the DNAME to the resolver, and the authoritative server responds positively to the A query but delays the DNAME response and later responds negatively, `named` may quit unexpectedly. Or, if a client queries for a CNAME and A record for the same name to the resolver, and the authoritative server responds positively to the A query but delays the CNAME response and later responds with a self-referential CNAME, the same failure may occur. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.18.11-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.

Join the discussion

Showing 1 to 10 of 15 results

Filters:Tag: cwe-617
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses