All findings

CVE-2026-33096 medium

MDASH and Claude share public credit on HTTP.sys denial of service

CVE-2026-33096 belongs to Microsoft's MDASH May cohort, while MSRC separately credits Calif.io researchers working with Claude.

Bug class
HTTP.sys denial of service
Affected codebase
Microsoft Windows HTTP.sys
Credited system
Microsoft MDASH
Also credited
Claude / Anthropic Research
Disclosed
May 12, 2026
Attribution
Direct source attribution
Severity
medium
Source status: Microsoft's MDASH campaign table includes CVE-2026-33096. The MSRC acknowledgment separately names Milad Nasr of Anthropic and Calif.io working with Claude, establishing shared direct attribution.

Summary

CVE-2026-33096 is a Windows HTTP.sys denial-of-service vulnerability shipped in Microsoft’s May 2026 Patch Tuesday release. Microsoft includes it in the 16-CVE MDASH cohort.

Shared attribution

The MSRC reporter line also credits Milad Nasr of Anthropic and Calif.io researchers working with Claude. This page preserves both discovery paths while the site-wide unique-CVE calculation counts the identifier once.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.