Source status: Microsoft's June 2026 CVRF acknowledgement for CVE-2026-49160 credits Quang Luong of Calif.io in collaboration with Codex. The public CVE record rates the issue as high severity.
Summary
CVE-2026-49160 is an HTTP.sys HTTP/2 denial-of-service vulnerability caused by uncontrolled resource consumption. Microsoft rates the issue high severity.
Attribution
The MSRC CVRF acknowledgement names Quang Luong of Calif.io in collaboration with Codex. The record does not spell out OpenAI in that credit string, but the same Calif.io/OpenAI Codex attribution pattern appears in Apache and Red Hat records for adjacent 2026 findings.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.