All systems

DepthFirst AI Platform

DepthFirst

DepthFirst's autonomous low-level-code analysis platform, with accepted NGINX, FFmpeg, and Apache HTTP Server campaigns.

5
Indexed entries
21
CVE IDs tracked
3
Critical/high entries
88%
Evidence index

What it is

DepthFirst describes its platform as an autonomous system for finding vulnerabilities in low-level code, including C and C++ systems where ordinary scanners often miss stateful memory-corruption paths.

The public record now spans NGINX Rift, a 21-finding FFmpeg campaign, and seven Apache HTTP Server CVEs. DepthFirst says its agents validate reachability with concrete reproducer inputs before reports reach maintainers.

What is verified

The ledger indexes five DepthFirst entries:

Attribution boundary

The NGINX, FFmpeg, and Apache campaign entries are not labeled as direct upstream AI attribution. Their public records corroborate the vulnerabilities, while DepthFirst supplies the autonomous-platform narrative. PostgreSQL CVE-2026-14679 is the narrower exception: PostgreSQL directly names “DepthFirst AI” in its reporter credit.

Why it matters

The combined record targets three mature, internet-facing native-code codebases and includes memory-corruption issues with public technical detail. It is concrete evidence of agentic analysis moving beyond toy programs into infrastructure where validation, coordination, and patch timing matter.

Sources

Attributed findings

Catalogued entries credited to DepthFirst.