All systems

DepthFirst AI Platform

DepthFirst

DepthFirst's autonomous low-level-code analysis platform, publicly tied to the NGINX Rift CVE cluster.

1
Indexed entries
4
CVE IDs tracked
1
Critical/high entries
88%
Evidence index

What it is

DepthFirst describes its platform as an autonomous system for finding vulnerabilities in low-level code, including C and C++ systems where ordinary scanners often miss stateful memory-corruption paths.

For Bugflation, the current public evidence centers on NGINX Rift: a May 2026 disclosure where DepthFirst says its system analyzed the NGINX source code, identified multiple memory-corruption issues, and produced proof material that was reported to NGINX/F5 through coordinated disclosure.

What is verified

The ledger indexes one DepthFirst entry:

Attribution boundary

This is not labeled as direct upstream AI attribution. The CVE records credit DepthFirst researchers and link the disclosure material, but the autonomous platform claim is made by DepthFirst itself. That makes the current Bugflation attribution self-reported: public vulnerability records corroborate the bugs, while DepthFirst supplies the AI-system narrative.

Why it matters

The NGINX cluster is notable because it targets a mature, internet-facing codebase and includes a critical memory-corruption issue with a published technical exploitability path. It is a concrete example of agentic analysis moving beyond toy programs into infrastructure software where validation, coordination, and patch timing matter.

Sources

Attributed findings

Catalogued entries credited to DepthFirst.