Open models helped find six NGINX vulnerabilities across five CVEs

cyb3rops · x · 2026-07-29

Open models found six NGINX vulnerabilities and five CVEs

Winfunc reports that it used GLM 5.1 and GLM 5.2 on the NGINX codebase and surfaced six security findings mapped to five CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, and CVE-2026-42533.

The findings include:

The report says all six vulnerabilities are credited in F5/NGINX advisories to Mufeed VH of Winfunc Research. It also notes the team reran scans across different model/provider traces, so the traces show the agent’s reasoning but do not prove which model found each CVE first.

Original post →

More from Safety

Safety channel →