Source status: Squid's upstream GHSA lists independent reports from Pavel Kohout of AISLE Research and Lam Jun Rong of Calif with Anthropic Research. AISLE supplies its analyzer attribution, while Calif's primary write-up identifies Claude Mythos directly. Upstream severity is Moderate 6.5.
Summary
CVE-2026-47729 allows a malicious FTP response to interfere with Squid’s HTTP gateway output and disclose memory from the proxy worker. Squid fixed the issue in 7.6 and rates it Moderate, CVSS 6.5.
Attribution
This is one vulnerability with independent reports, not two findings. Squid’s advisory supplies the reporter trail; Calif’s disclosure connects its report to Claude Mythos, while AISLE’s public registry connects Pavel Kohout’s report to the AISLE platform.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.