All findings

CVE-2026-49975, CVE-2026-6385 medium

Calif.io credits OpenAI Codex on Apache httpd and FFmpeg CVEs

Apache and Red Hat/CVE records credit Quang Luong of Calif.io in collaboration with OpenAI Codex for a mod_http2 denial of service and an FFmpeg DVD subtitle parser memory-safety bug.

Bug class
Denial-of-service and media-parser memory corruption
Affected codebase
Apache HTTP Server, FFmpeg
Credited system
OpenAI Aardvark / Codex Security
Disclosed
June 8, 2026
Attribution
Direct source attribution
Severity
medium
Source status: Apache's 2.4.68 vulnerability page directly credits Quang Luong of Calif.IO in collaboration with OpenAI Codex for CVE-2026-49975. The CVE record for CVE-2026-6385 carries Red Hat's finder credit to Quang Luong, Calif.io, and OpenAI Codex.

Summary

Two public 2026 vendor/CNA records now credit Calif.io work performed in collaboration with OpenAI Codex.

CVE-2026-49975 is a moderate Apache HTTP Server mod_http2 denial of service affecting 2.4.17 through 2.4.67 and fixed in 2.4.68. CVE-2026-6385 is an FFmpeg DVD subtitle parser signed-integer-overflow issue that can cause denial of service and potentially arbitrary code execution when processing malicious MPEG-PS/VOB media.

Attribution

This is a direct-attribution cluster. Apache provides the Codex credit on its own vulnerability page. For FFmpeg, the CVE record contains Red Hat’s public credit string naming OpenAI Codex.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.