Summary
CVE-2026-45447 is a heap use-after-free in OpenSSL’s PKCS7_verify()
function. OpenSSL says a crafted PKCS#7 or S/MIME signed message can trigger
memory corruption, with impact ranging from crash to potential code execution
depending on application behavior and platform hardening.
Attribution
This entry counts only CVE-2026-45447 from the June 2026 OpenSSL batch because the OpenSSL primary source explicitly names the Claude collaboration. Other June OpenSSL rows credited only to Anthropic employees are not counted here without public AI-workflow attribution.
References
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.