# CWE-617: Reachable Assertion

> As of 2026-10-05, CWE-617 (Reachable Assertion) underlies 13 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 2 tracked threats.

**Last updated:** 2026-10-05

## What is CWE-617?

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

While assertion is good for catching logic errors and reducing the chances of reaching more serious vulnerability conditions, it can still lead to a denial of service. For example, if a server handles multiple simultaneous connections, and an assert() occurs in one single connection that causes all other connections to be dropped, this is a reachable assertion that leads to a denial of service.

CWE-617 is a base-level weakness in MITRE’s Common Weakness Enumeration. Applicable platforms: Not Language-Specific; C; Java; Rust; Not Technology-Specific.

_Source: [MITRE CWE](https://cwe.mitre.org/data/definitions/617.html) (CWE-617 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data._

## Consequences

- **Availability** — DoS: Crash, Exit, or Restart. An attacker that can trigger an assert statement can still lead to a denial of service if the relevant code can be triggered by an attacker, and if the scope of the assert() extends beyond the attacker's own session.

_Source: MITRE CWE, common consequences._

## How CWE-617 is exploited in the wild

Threadlinqs maps 13 CVEs to CWE-617, published between 2026-05-20 and 2026-09-21. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 8 high, 3 medium, 1 low. The highest EPSS score in the set is 0.4% (CVE-2026-94623), the modelled probability of exploitation in the next 30 days. 2 tracked threats reference CWE-617 directly or through a CVE it covers; the most recent is “Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)” (2026-08-01). Affected products concentrate in The Libreswan Project (3), strukturag (2), AcademySoftwareFoundation (1), among 7 vendors in total.

## Vulnerabilities (CVEs)

All 13 CVEs mapped to CWE-617, CISA KEV first, then by CVSS score.

- [CVE-2026-94623](https://intel.threadlinqs.com/cve/CVE-2026-94623) — CVSS 7.5 high · EPSS 0.4% · published 2026-09-21
- [CVE-2026-44435](https://intel.threadlinqs.com/cve/CVE-2026-44435) — CVSS 7.5 high · EPSS 0.2% · published 2026-07-16
- [CVE-2025-56362](https://intel.threadlinqs.com/cve/CVE-2025-56362) — CVSS 7.5 high · EPSS 0.2% · published 2026-07-14
- [CVE-2026-5946](https://intel.threadlinqs.com/cve/CVE-2026-5946) — CVSS 7.5 high · EPSS 0.0% · published 2026-05-20
- [CVE-2025-56365](https://intel.threadlinqs.com/cve/CVE-2025-56365) — CVSS 7.5 high · published 2026-07-14
- [CVE-2026-12413](https://intel.threadlinqs.com/cve/CVE-2026-12413) — CVSS 7.5 high · published 2026-07-02
- [CVE-2026-50721](https://intel.threadlinqs.com/cve/CVE-2026-50721) — CVSS 7.5 high · published 2026-07-02
- [CVE-2026-50722](https://intel.threadlinqs.com/cve/CVE-2026-50722) — CVSS 7.5 high · published 2026-07-02
- [CVE-2026-62377](https://intel.threadlinqs.com/cve/CVE-2026-62377) — CVSS 4.3 medium · EPSS 0.4% · published 2026-08-18
- [CVE-2026-62289](https://intel.threadlinqs.com/cve/CVE-2026-62289) — CVSS 4.3 medium · EPSS 0.3% · published 2026-08-18
- [CVE-2026-82590](https://intel.threadlinqs.com/cve/CVE-2026-82590) — CVSS 4.3 medium · EPSS 0.3% · published 2026-08-30
- [CVE-2026-76926](https://intel.threadlinqs.com/cve/CVE-2026-76926) — CVSS 3.1 low · EPSS 0.1% · published 2026-08-19
- [CVE-2026-53532](https://intel.threadlinqs.com/cve/CVE-2026-53532) — EPSS 0.2% · published 2026-08-24

## Affected vendors

- **The Libreswan Project** — 3 CVEs
- **strukturag** — 2 CVEs
- **AcademySoftwareFoundation** — 1 CVE
- [ISC](https://intel.threadlinqs.com/vendors/isc) — 1 CVE
- [Wireshark Foundation](https://intel.threadlinqs.com/vendors/wireshark-foundation) — 1 CVE
- [h2o](https://intel.threadlinqs.com/vendors/h2o) — 1 CVE
- [vllm-project](https://intel.threadlinqs.com/vendors/vllm-project) — 1 CVE

## Threat activity

2 tracked threats cite CWE-617:

- [Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)](https://intel.threadlinqs.com/threat/TL-2026-1807) — HIGH · 2026-08-01
- [BIND 9 Multi-CVE Disclosure (May 2026) — Heap UAF in DoH (CVE-2026-3593), SIG(0) UAF (CVE-2026-5947), Resolver Resend Loop DoS (CVE-2026-5950), CLASS!=IN Assertion DoS (CVE-2026-5946), Glue Amplification (CVE-2026-3592), GSS-API TKEY Memory Exhaustion (CVE-2026-3039)](https://intel.threadlinqs.com/threat/TL-2026-0599) — HIGH · 2026-05-27

## Mitigations

- **Implementation**: Make sensitive open/close operation non reachable by directly user-controlled data (e.g. open/close resources)
- **Implementation / Input Validation**: Perform input validation on user data.

_Source: MITRE CWE, potential mitigations._

## Detection methods (MITRE CWE)

- **Automated Static Analysis**: Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

_Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher._

## Related weaknesses

- [CWE-705](https://cwe.mitre.org/data/definitions/705.html)
- [CWE-670](https://cwe.mitre.org/data/definitions/670.html)

Canonical: https://intel.threadlinqs.com/cwe/CWE-617
Source definition: https://cwe.mitre.org/data/definitions/617.html
Detection rules and IOCs for threats exploiting CWE-617 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
