All findings

CVE-2026-49420 high

Atuin and AISLE converge on FreeBSD libalias stack overflow

FreeBSD's libalias advisory directly credits Atuin-assisted research, while AISLE independently claims discovery of the same remotely reachable stack-overflow CVE.

Bug class
Remotely reachable stack buffer overflow
Affected codebase
FreeBSD libalias
Credited system
Atuin Automated Vulnerability Discovery Engine
Also credited
AISLE (self-reported)
Disclosed
June 30, 2026
Attribution
Direct source attribution
Severity
high
Source status: FreeBSD directly names the Atuin Automated Vulnerability Discovery System and other researchers. AISLE's public discovery registry supplies the AI-platform attribution for its independent report.

Summary

CVE-2026-49420 is a stack overflow in FreeBSD’s network address translation library. The advisory describes exposure through applications that pass attacker-controlled traffic into libalias, creating denial-of-service and potential code-execution impact.

The finding is useful evidence of independent AI-assisted convergence. Atuin, UC Berkeley Antiproof researchers, and AISLE appear in the reporting trail.

Attribution

Atuin receives direct attribution because the FreeBSD advisory names the automated discovery system. AISLE is listed separately with self-reported AI attribution: the vulnerability is upstream-confirmed, while AISLE’s registry connects its researcher credit to the platform.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.