All findings

CVE-2026-47729 medium

AISLE and Claude Mythos independently report Squid FTP memory disclosure

Squid's advisory records independent reports from AISLE and Calif/Anthropic researchers for an FTP gateway response-smuggling flaw that can expose worker memory.

Bug class
Response smuggling and process-memory disclosure
Affected codebase
Squid FTP gateway
Credited system
AISLE
Also credited
Claude Mythos Preview (direct)
Disclosed
July 16, 2026
Attribution
Self-reported attribution
Severity
medium
Source status: Squid's upstream GHSA lists independent reports from Pavel Kohout of AISLE Research and Lam Jun Rong of Calif with Anthropic Research. AISLE supplies its analyzer attribution, while Calif's primary write-up identifies Claude Mythos directly. Upstream severity is Moderate 6.5.

Summary

CVE-2026-47729 allows a malicious FTP response to interfere with Squid’s HTTP gateway output and disclose memory from the proxy worker. Squid fixed the issue in 7.6 and rates it Moderate, CVSS 6.5.

Attribution

This is one vulnerability with independent reports, not two findings. Squid’s advisory supplies the reporter trail; Calif’s disclosure connects its report to Claude Mythos, while AISLE’s public registry connects Pavel Kohout’s report to the AISLE platform.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.