Summary
After the previous Bugflation cutoff, AISLE’s public stream added ten identifiable CVEs outside the separately indexed curl and Squid campaigns. The affected projects cover developer infrastructure, CMS software, packet analysis, network configuration, workflow automation, and audio libraries.
Attribution boundary
The issues and fixes are independently visible upstream. The claim that AISLE’s AI-native engine discovered each one comes from AISLE’s own registry, so the cluster is labeled self-reported. It should be split later if upstream projects publish direct AISLE-system credit or materially different severity details.
References
- AISLE CVE discovery registry
- Foreman 3.18 release notes
- Gitea 1.25.5 release
- Joomla security advisory
- Wireshark WNPA-SEC-2026-55
- n8n advisory GHSA-vjf3-2gpj-233v
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.