All findings

CVE-2026-29167, CVE-2026-29170 low

Apache httpd credits AISLE Research on two 2.4.68 CVEs

Apache's upstream 2.4.68 security record credits AISLE Research on two vulnerabilities in HTTP Server request and module handling.

Bug class
Request-processing and module-boundary vulnerabilities
Affected codebase
Apache HTTP Server
Credited system
AISLE
Disclosed
June 8, 2026
Attribution
Self-reported attribution
Severity
low
Source status: Apache's vulnerability page credits Pavel Kohout of AISLE Research on both accepted CVEs, while AISLE's registry supplies the autonomous-system attribution. Apache rates both issues Low.

Summary

The Apache 2.4.68 release adds two upstream credits to AISLE’s public record. They are indexed separately from the DepthFirst, Striga, and Codex-assisted Apache findings in the same release so each coordinated campaign remains auditable.

Apache rates CVE-2026-29167 and CVE-2026-29170 Low. The affected-vendor record names the researcher and company, not the AISLE analyzer, so the AI-system attribution remains self-reported.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.