What it is
DepthFirst describes its platform as an autonomous system for finding vulnerabilities in low-level code, including C and C++ systems where ordinary scanners often miss stateful memory-corruption paths.
The public record now spans NGINX Rift, a 21-finding FFmpeg campaign, and seven Apache HTTP Server CVEs. DepthFirst says its agents validate reachability with concrete reproducer inputs before reports reach maintainers.
What is verified
The ledger indexes five DepthFirst entries:
- CVE-2026-42945, CVE-2026-42946, CVE-2026-40701, and CVE-2026-42934, a four-CVE NGINX cluster led by the critical NGINX Rift rewrite-module heap overflow. DepthFirst says its autonomous platform found the issues; NVD and F5-linked CVE records corroborate the public vulnerabilities and fixes.
- Nine FFmpeg CVEs, CVE-2026-39210 through CVE-2026-39218, plus twelve additional fixed no-CVE reports in one coordinated campaign.
- Six Apache HTTP Server CVEs directly credited to DepthFirst researchers.
- Shared DepthFirst/Striga credit on Apache CVE-2026-44631.
- PostgreSQL CVE-2026-14679, where the project’s security page directly credits
Zheng Yu of DepthFirst AI on an out-of-bounds write in
CREATE STATISTICS.
Attribution boundary
The NGINX, FFmpeg, and Apache campaign entries are not labeled as direct upstream AI attribution. Their public records corroborate the vulnerabilities, while DepthFirst supplies the autonomous-platform narrative. PostgreSQL CVE-2026-14679 is the narrower exception: PostgreSQL directly names “DepthFirst AI” in its reporter credit.
Why it matters
The combined record targets three mature, internet-facing native-code codebases and includes memory-corruption issues with public technical detail. It is concrete evidence of agentic analysis moving beyond toy programs into infrastructure where validation, coordination, and patch timing matter.