Home

Methodology Last checked July 20, 2026

Methodology

Bugflation is a source-led ledger. We count public evidence of AI-attributed vulnerability discovery, not private telemetry or inferred model usage.


What counts

A finding enters the ledger when all of the following are true:

Shared credit and counting

One vulnerability can have several independent discovery paths. A finding may therefore name a primary credited system and additional credited systems, each with its own attribution strength. The same CVE remains one unique identifier in site-wide totals and is not multiplied by the number of reporters, products, or release notes that mention it.

Attribution labels

Attribution is not binary. The ledger uses three labels:

What we exclude

Severity

When a CVE has an authoritative CVSS score, the ledger follows the vendor or CNA severity where practical. Upstream severity takes precedence over the score shown in an AI vendor's tracker. For clusters that group several CVEs in one release, the severity is editorial and is explained in the entry.

Evidence index

System profiles include an evidence index. It is not a capability score. It reflects the strength and density of public sources: direct upstream credits score higher than self-reported claims, and entries with multiple corroborating sources score higher than single-source entries.

Correction policy

If an entry overstates impact, mislabels attribution, or misses a primary source, we revise it. Corrections should be sent to hello@bugflation.com with links to the relevant source material.

Current source set

The current ledger is based on public material from Google Project Zero, Google's security announcements, OSS-Fuzz updates, Chrome release notes, Apple security advisories, Mozilla security advisories, Anthropic research posts, FreeBSD security advisories, OpenSSL and wolfSSL release material, GnuPG and Libgcrypt release material, Microsoft Security Blog posts, MSRC CVRF feeds, OpenAI research and product-security posts, NVD, CVE.org, GitHub reviewed advisories, XBOW publications, AISLE publications, Elastic security announcements, Calif.io MADBugs write-ups, Xint/Theori CopyFail material, the Xint public bug tracker, Linux kernel commits, ZeroPath research posts and Wall of Fame material, ProFTPD and Spinnaker release/advisory records, FFmpeg patch links, sudo upstream commits, Qualys CrackArmor material, Striga research and CVE material, Apache HTTP Server advisories, Apache NiFi advisories, oss-security postings, Bynario research posts, Bynario-linked Linux kernel commits, Apple product-security advisories, Horizon3.ai ActiveMQ research, Microsoft Security Blog and MSRC material for codename MDASH, V12 Fragnesia material, Linux netdev patch mail, distribution trackers for CVE-2026-46300, Anthropic's Project Glasswing CVD dashboard and ledger, DepthFirst NGINX Rift material, F5/NGINX-linked CVE records, Palo Alto Networks frontier-AI posts, security advisories, and advisory CSV, HackerOne policy material, LibreOffice security advisories, Cloud Foundry UAA advisories, HashiCorp security bulletins, PostgreSQL security pages, Joomla Security Centre advisories, TYPO3 advisories, Symfony/Twig security releases, Tencent Xuanwu Lab Atuin material, and distribution trackers for Exim and Libgcrypt CVEs, plus OpenAI Daybreak and Patch the Planet, dnsmasq maintainer records, curl's advisory database, Squid advisories, GitHub Security Lab Taskflow advisories, Z.AI GLM credits, DepthFirst's FFmpeg campaign, V12's public PoC repository, and pwn.ai disclosures.