Open models helped find six NGINX vulnerabilities across five CVEs
cyb3rops · x · 2026-07-29
Open models found six NGINX vulnerabilities and five CVEs
Winfunc reports that it used GLM 5.1 and GLM 5.2 on the NGINX codebase and surfaced six security findings mapped to five CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, and CVE-2026-42533.
The findings include:
- two heap overflows in HTTP/2 upstream request builders
- one heap overflow in the rewrite engine
- one heap overflow in the stream scripting engine
- one HTTP/2 frame-injection bug
- one mTLS authorization bypass where a revoked certificate was still accepted
The report says all six vulnerabilities are credited in F5/NGINX advisories to Mufeed VH of Winfunc Research. It also notes the team reran scans across different model/provider traces, so the traces show the agent’s reasoning but do not prove which model found each CVE first.
More from Safety
- NVIDIA and 70+ Companies Sign Open Letter Supporting Open-Weight AI Models — NVIDIAAI · 2026-07-30
- Overly Strict Guardrails: Claude Blocks Enterprise Cyber Defense Investigations — RexDouglass · 2026-07-30
- AI Copyright Moats Fail, Prompting Shift to Government Protection — RexDouglass · 2026-07-30
- Sam Altman Tells Capitol Hill: Other Systems Hacked by OpenAI Are Possible — ns123abc · 2026-07-30
- OpenClaw Exposes Critical RCE Flaw, 50k+ Nodes Compromised — ericelliott_ · 2026-07-30
- xAI Sues Minnesota to Block Anti-Nudification App Law — The Verge AI · 2026-07-30