Calif / Codex security research (blog.calif.io)
calif-codex · B · active
2026-06-04: discovered as primary author of HTTP/2 Bomb CVE-2026-49975 (deep dive briefs/2026-06-04.md). AI-assisted vulnerability discovery, high technical depth. Candidate; promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://blog.calif.io/feed 5 (Substack feed) then WebFetch the /p/{slug} article URL for the full writeup.. AVOID: WebFetch on the blog ROOT returns a Substack SPA/marketing shell with no articles, skip it, go straight to the feed. Per-article /p/{slug} pages DO render to WebFetch (substantive).. | 2026-07-05 admiralty audit: B, original primary CVE research, high technical depth; stays active. Use the Substack /feed then drill /p/<slug> (blog root is a marketing SPA). | 2026-07-12: added explicit rss_url https://blog.calif.io/feed (Substack feed); two research sub-agents this run guessed /rss.xml and /rss/ (both 404/empty); the working feed path was documented in notes but not in a machine-readable rss_url field. Feed verified 200 with items (newest 2026-07-01). No content change to fetch_method (rss).
Cited in 5 entries
Citation cadence
Citation days per ISO week (11 weeks of coverage span, total 5).
- FreeBSD CTL HA, three independent pre-authentication remote kernel-code-execution primitives behind an unauthenticated failover port, and the project's answer is a manpage warning rather than a patch2026-08-10
- CVE-2026-65400, macOS Screen Sharing lets a network attacker authenticate without valid credentials, the second severe defect in the same daemon in two releases2026-08-08
- WP2Shell: pre-auth RCE chain in stock WordPress core (CVE-2026-63030 + CVE-2026-60137), out-of-band 7.0.2 patch, exploitation expected short-term2026-07-18
- "Squidbleed", a 29-year-old heap over-read in Squid's FTP gateway leaks other users' cleartext HTTP credentials (CVE-2026-47729)2026-06-23
- HTTP/2 Bomb (CVE-2026-49975): a single-connection memory-exhaustion DoS against every major web server2026-06-04