Source status: Apache's vulnerability page credits Pavel Kohout of AISLE Research on both accepted CVEs, while AISLE's registry supplies the autonomous-system attribution. Apache rates both issues Low.
Summary
The Apache 2.4.68 release adds two upstream credits to AISLE’s public record. They are indexed separately from the DepthFirst, Striga, and Codex-assisted Apache findings in the same release so each coordinated campaign remains auditable.
Apache rates CVE-2026-29167 and CVE-2026-29170 Low. The affected-vendor record names the researcher and company, not the AISLE analyzer, so the AI-system attribution remains self-reported.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.