All findings

CVE-2026-45447 high

OpenSSL credits Claude-assisted Calif.io report for PKCS7_verify use-after-free

OpenSSL's June 2026 vulnerability database credits Thai Duong of Calif.io in collaboration with Claude and Anthropic Research for CVE-2026-45447, a high-severity PKCS7_verify() heap use-after-free.

Bug class
PKCS7/S/MIME heap use-after-free
Affected codebase
OpenSSL
Credited system
Claude / Anthropic Research
Disclosed
June 9, 2026
Attribution
Direct source attribution
Severity
high
Source status: OpenSSL's vulnerability database directly credits Thai Duong of Calif.io in collaboration with Claude and Anthropic Research. The OpenSSL page rates the issue high and lists fixed releases across supported and premium support branches.

Summary

CVE-2026-45447 is a heap use-after-free in OpenSSL’s PKCS7_verify() function. OpenSSL says a crafted PKCS#7 or S/MIME signed message can trigger memory corruption, with impact ranging from crash to potential code execution depending on application behavior and platform hardening.

Attribution

This entry counts only CVE-2026-45447 from the June 2026 OpenSSL batch because the OpenSSL primary source explicitly names the Claude collaboration. Other June OpenSSL rows credited only to Anthropic employees are not counted here without public AI-workflow attribution.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.