Summary
The tracker-backed expansion adds eighteen CVEs beyond Bugflation’s existing Apache HTTP/2 double-free entry. It includes four Logseq CVEs, two Ollama update issues, two pac4j issues, three Tomcat issues, and individual records across the other affected projects.
CVE-2026-44631 is intentionally not in this cluster. It has independent Striga and DepthFirst attribution and is represented on its own shared page.
Attribution boundary
The affected projects and patches are independently public. The statement that Striga’s AI source-code auditing platform found each issue comes from Striga’s tracker and research posts, so the cluster remains self-reported rather than direct upstream AI attribution.
References
- Striga CVE tracker
- CERT Polska: Logseq CVE-2026-9279 cluster
- Apache Shiro security reports
- Apple container advisory
- CERT Polska: Ollama CVE cluster
- pac4j security advisory
- axios advisory
- n8n advisory
- OpenClaw advisory
- FreshRSS advisory
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.