All findings

CVE-2026-23967, CVE-2026-5807, CVE-2026-6475 high

Atuin public CVE-backed cluster spans sm-crypto, Vault, and PostgreSQL

Public advisories credit Tencent Xuanwu Lab's Atuin Automated Vulnerability Discovery Engine on CVEs in sm-crypto, HashiCorp Vault, and PostgreSQL.

Bug class
Cryptographic signature malleability, denial of service, and symlink following
Affected codebase
sm-crypto, HashiCorp Vault, PostgreSQL
Credited system
Atuin Automated Vulnerability Discovery Engine
Disclosed
May 14, 2026
Attribution
Direct source attribution
Severity
high
Source status: GitHub, HashiCorp, and PostgreSQL public records credit Atuin Automated Vulnerability Discovery Engine. Tencent Xuanwu Lab's Atuin write-up describes the system as based on large language model technology.

Summary

Atuin now has multiple public CVE-backed credits:

Attribution

The public project advisories name Atuin Automated Vulnerability Discovery Engine. The separate Tencent Xuanwu Lab write-up establishes that Atuin is an automated vulnerability discovery system based on large language model technology, satisfying the AI-system requirement without relying on inference from the advisory names alone.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.