CWE-617

CWE-617 · 8 records · 4 with a public proof-of-concept

Records the NVD classes under CWE-617, highest CVSS first.

  1. HIGH 7.5CVE-2026-94623public PoC

    vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated deployments. Attackers can…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.5CVE-2026-92971public PoC

    InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers can submit a migration_request with an empty remote_block_id…

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.5CVE-2026-80274

    If a BIND resolver sends a query for a DNSSEC-signed authoritative zone, and the authoritative server replies with a valid wildcard answer and signed NSEC3 proof, followed by an unsigned NSEC at the same owner name, it will trigger an unexpected program exit. …

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.5CVE-2026-76163

    If BIND is loaded with a "`named.conf`" file that contains no global "`options`" block, an attacker can send a query of QTYPE TKEY which may cause an assertion failure and subsequent unexpected program exit. This issue affects BIND 9 versions 9.20.0 through 9.…

    AI risk analysis on Exploit-DB.ai →

  5. MEDIUM 5.5CVE-2026-88341public PoC

    A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causi…

    AI risk analysis on Exploit-DB.ai →

  6. MEDIUM 5.3CVE-2026-8674

    Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which abort…

    AI risk analysis on Exploit-DB.ai →

  7. MEDIUM 5.3CVE-2026-73438

    On affected platforms running Arista EOS with Open Shortest Path First version 3 (OSPFv3) configured, an unauthenticated attacker on the same OSPFv3 broadcast domain can send a specially crafted set of packets that can cause the Ospf3 agent to restart unexpect…

    AI risk analysis on Exploit-DB.ai →

  8. MEDIUM 4.3CVE-2026-92416public PoC

    A vulnerability has been found in Open5GS up to 2.8.0. Affected by this issue is the function smf_n4_handle_session_report_request of the file src/smf/n4-handler.c of the component PFCP Session Report Request Handler. The manipulation leads to reachable assert…

    AI risk analysis on Exploit-DB.ai →