All findings

CVE-2026-44631 low

DepthFirst and Striga share credit on Apache httpd heap underflow

Apache's 2.4.68 security record credits both DepthFirst and Bartlomiej Dmitruk of Striga on a heap-underflow vulnerability.

Bug class
Heap underflow
Affected codebase
Apache HTTP Server
Credited system
DepthFirst
Also credited
Striga AI
Disclosed
June 8, 2026
Attribution
Self-reported attribution
Severity
low
Source status: Apache directly credits DepthFirst and Bartlomiej Dmitruk of Striga for the accepted vulnerability. Each company supplies the AI-platform context for its own research workflow. Apache rates the issue Low.

Summary

CVE-2026-44631 is a heap-underflow issue fixed in Apache HTTP Server 2.4.68. Apache rates the issue Low and lists reports from both DepthFirst and Striga.

Attribution

Upstream confirms the researchers and accepted flaw, while the companies’ own materials connect those reports to their AI-assisted platforms. Both AI labels are therefore self-reported and the CVE is counted only once globally.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.