All articles

Bugflation Editorial auditevidencemethodology

July 2026 Source Audit: The Public Ledger Broadens

A primary-source audit adds post-cutoff disclosures, backfills public campaigns, preserves shared attribution, and separates tracker claims from upstream severity.


The July audit changes the scale of Bugflation’s public ledger. It now contains 98 grouped finding pages referencing 383 unique CVE IDs, while preserving the distinction between one CVE, one disclosure campaign, and one AI-system credit.

The increase comes from two different sources. Some disclosures appeared after the previous June 22 cutoff. Others were already public but lived in vendor trackers, upstream commit messages, or coordinated campaign pages that had not yet been reconciled against the ledger.

What was added

The strongest post-cutoff additions are direct affected-vendor credits:

OpenAI’s Patch the Planet disclosure also made several previously private workflows auditable. The ledger now includes four dnsmasq CVEs, Firefox CVE-2026-8390, three FreeBSD CVEs, a patched OpenBSD kernel use-after-free, two OpenAI-linked public Chrome V8 CVEs, and the HTTP/2 Bomb campaign. Only one of the Chrome CVEs is directly named as Codex Security; the other retains a qualified Daybreak campaign attribution. Larger private totals remain outside the finding count.

The historical backlog was larger

The largest backfills are campaign-shaped:

These additions are grouped by coordinated campaign. A campaign with twenty fixes is one finding page, but every public CVE remains visible to the global unique-ID counter.

Shared attribution is now first-class

One CVE can have more than one independent AI-assisted discovery path. The content schema now represents additional credited systems directly. System pages resolve the attribution for the system being viewed, while shared finding lists and RSS pair every credited system with its own evidence label.

That matters for Squid CVE-2026-47729, FreeBSD CVE-2026-49420, Apache CVE-2026-44631, and Microsoft CVE-2026-33096. Each has public evidence for more than one system or workflow. The ledger preserves those overlaps instead of forcing an arbitrary winner.

Tracker totals remain context

AISLE’s registry headline says 268 assigned CVEs, but its headline, pagination, and retrievable rows do not currently reconcile. Xint’s tracker has 51 rows, with the newest still embargoed. Anthropic’s public CVD ledger still exposes 27 fixed rows even though its dashboard describes a much larger private pipeline.

Bugflation therefore does not turn vendor headline numbers into findings. Tracker rows are discovery leads. They enter the ledger only after the affected project, patch, advisory, or public CVE trail is checked.

The same rule applies to severity. curl’s own Low or Medium classification wins over a vendor tracker score, and Apache’s Low or Moderate ratings cap the AISLE and DepthFirst httpd clusters at Low and Medium. Upstream projects are the authoritative source for impact labels used by the ledger.

The operational lesson

The bottleneck is increasingly reconciliation: matching operator claims to upstream identifiers, separating shared credits, normalizing severity, and tracking accepted issues that have no CVE.

The site now derives each system’s indexed-entry, unique-CVE, and high-impact counts from the finding ledger at build time. That does not replace editorial review, but it removes one class of manual count drift as the public record grows.


Published July 20, 2026 by Bugflation Editorial. Follow new articles and findings through the RSS feed.