All findings

CVE-2026-4890 + 3 more medium

Codex Security independently identifies four fixed dnsmasq CVEs

OpenAI says Codex Security independently identified vulnerable patterns corresponding to four dnsmasq CVEs fixed in the 2.92rel2 security release.

Bug class
DNS and DHCP parser memory-safety and denial-of-service flaws
Affected codebase
dnsmasq
Credited system
OpenAI Aardvark / Codex Security
Also credited
OpenAI Daybreak
Disclosed
June 22, 2026
Attribution
Direct source attribution
Severity
medium
Source status: OpenAI's Patch the Planet disclosure names Codex Security and the four CVE IDs. dnsmasq's maintainer archive publishes the corresponding credits and patches in the 2.92rel2 security release.

Summary

OpenAI reports that Codex Security independently recognized vulnerable patterns matching four of the six CVEs fixed in dnsmasq 2.92rel2. The dnsmasq maintainer publishes per-CVE credit and patch files for the release.

The entry counts only the four identifiers OpenAI names. It does not absorb the other two release CVEs or OpenAI’s broader private campaign totals.

Attribution

OpenAI’s primary disclosure establishes the AI-system role, while dnsmasq’s maintainer archive independently establishes the accepted patches and release.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.