All findings

CVE-2026-9279 + 17 more critical

Striga's public tracker adds eighteen validated CVEs across eleven projects

Striga's AI-auditing record extends beyond its existing Apache entry into Logseq, Shiro, Apple container, Ollama, pac4j, Tomcat, axios, n8n, Mattermost, OpenClaw, and FreshRSS.

Bug class
RCE, authorization bypass, credential theft, denial-of-service, and injection flaws
Affected codebase
Logseq, Apache Shiro, Apple container, Ollama, pac4j, Tomcat, axios, n8n, Mattermost Desktop, OpenClaw, and FreshRSS
Credited system
Striga AI
Disclosed
June 9, 2026
Attribution
Self-reported attribution
Severity
critical
Source status: Striga's CVE tracker supplies the AI-platform attribution. CVE records, vendor GHSAs, Apache advisories, CERT Polska, and project releases independently corroborate the vulnerabilities and fixes.

Summary

The tracker-backed expansion adds eighteen CVEs beyond Bugflation’s existing Apache HTTP/2 double-free entry. It includes four Logseq CVEs, two Ollama update issues, two pac4j issues, three Tomcat issues, and individual records across the other affected projects.

CVE-2026-44631 is intentionally not in this cluster. It has independent Striga and DepthFirst attribution and is represented on its own shared page.

Attribution boundary

The affected projects and patches are independently public. The statement that Striga’s AI source-code auditing platform found each issue comes from Striga’s tracker and research posts, so the cluster remains self-reported rather than direct upstream AI attribution.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.