All findings

CVE-2026-49160 high

MSRC credits Codex collaboration for HTTP.sys denial of service

Microsoft's June 2026 CVRF feed credits Quang Luong of Calif.io in collaboration with Codex for CVE-2026-49160, an HTTP.sys HTTP/2 denial-of-service vulnerability.

Bug class
HTTP/2 resource-consumption denial of service
Affected codebase
Microsoft Windows HTTP.sys
Credited system
OpenAI Aardvark / Codex Security
Disclosed
June 9, 2026
Attribution
Direct source attribution
Severity
high
Source status: Microsoft's June 2026 CVRF acknowledgement for CVE-2026-49160 credits Quang Luong of Calif.io in collaboration with Codex. The public CVE record rates the issue as high severity.

Summary

CVE-2026-49160 is an HTTP.sys HTTP/2 denial-of-service vulnerability caused by uncontrolled resource consumption. Microsoft rates the issue high severity.

Attribution

The MSRC CVRF acknowledgement names Quang Luong of Calif.io in collaboration with Codex. The record does not spell out OpenAI in that credit string, but the same Calif.io/OpenAI Codex attribution pattern appears in Apache and Red Hat records for adjacent 2026 findings.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.