Summary
Two public 2026 vendor/CNA records now credit Calif.io work performed in collaboration with OpenAI Codex.
CVE-2026-49975 is a moderate Apache HTTP Server mod_http2 denial of service
affecting 2.4.17 through 2.4.67 and fixed in 2.4.68. CVE-2026-6385 is an FFmpeg
DVD subtitle parser signed-integer-overflow issue that can cause denial of
service and potentially arbitrary code execution when processing malicious
MPEG-PS/VOB media.
Attribution
This is a direct-attribution cluster. Apache provides the Codex credit on its own vulnerability page. For FFmpeg, the CVE record contains Red Hat’s public credit string naming OpenAI Codex.
References
- Apache HTTP Server 2.4 vulnerabilities
- CVE record: CVE-2026-49975
- CVE record: CVE-2026-6385
- NVD: CVE-2026-6385
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.