PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlogVulnerability disclosures
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert

Resources · Vulnerability Disclosures

Anthropic's Coordinated Vulnerability Disclosure Dashboard

A structured view of the vulnerability disclosure data that Anthropic publishes for its Coordinated Vulnerability Disclosure (CVD) programme, in which Claude models find vulnerabilities in open-source software and the findings are reported to project maintainers. Every figure, record and ledger entry on this page comes from Anthropic's public CVD dashboard, ledger and methodology pages.

Last UpdatedAs shown on Anthropic's dashboard
Counts as ofOctober 2, 2026
SnapshotRevision 35
TimezoneUTCAll dates and times on this page

Independent presentation by IntelliXBOM of data published by Anthropic. IntelliXBOM is not affiliated with Anthropic and this page is not endorsed by Anthropic. Anthropic's own pages are the authoritative source; see Source & attribution. Retrieved October 7, 2026.

01 · Overview

What this dashboard tracks

Anthropic uses Claude models, including an early snapshot of Claude Mythos Preview, to find security vulnerabilities in open-source software. We partner with external security research firms to triage findings, validate them, and report human-reviewed vulnerabilities, prioritizing critical- and high-severity ones, to the software's maintainers under our Coordinated Vulnerability Disclosure policy (opens Anthropic site in a new tab). This page tracks the findings that we've disclosed, and, in line with our policy, publishes details of the ones whose disclosure window has now closed.

As of October 2, 2026, we've disclosed 6,157 vulnerabilities across 591 open source projects. To our knowledge, 516 of these have been patched. Across all findings in the ledger, 584 identifiers have been issued: 219 CVE records and 365 GitHub Security Advisories (a single finding may carry both). In other cases, maintainers have shipped a fix without publishing an advisory. The number of vulnerabilities we've disclosed is a subset of the total number of vulnerabilities that Mythos Preview (and other Claude models) has found, since the process of independent human triage and review is the rate limiting step.

This page covers a headline count of the vulnerabilities we've disclosed. For those vulnerabilities we've disclosed and where the disclosure window has now closed, it also includes identifier records (CVE & GHSA) and finding details, further below.

Finally, it includes a disclosure ledger. The ledger lists hash commitments for findings we have reported or plan to report. The details we publish later can be checked against them.

Anthropic, Coordinated vulnerability disclosure dashboard (opens Anthropic site in a new tab)

02 · Key statistics

Headline figures

All findings, as of October 2, 2026. These are the unfiltered headline figures. Use the pipeline filters below to narrow them by severity, assessment source and discovery date.

Vulnerabilities disclosed6,157Total reported to maintainers
Open-source projects591Projects the disclosed vulnerabilities span
Patched upstream516Maintainers created and released a fix
Identifiers issued584219 CVE records · 365 GHSAs
Acknowledged by maintainer5,103Maintainers responded to the report
Candidates29,439Vulnerability hypotheses before triage
True positive rate92.7%5,674 confirmed valid of 6,123 firm-reviewed
Ledger entries6,597SHA-3-512 hash commitments

03 · Disclosure pipeline

From candidate to advisory

Anthropic's flowchart of the disclosure process, filterable by severity, assessment source and discovery date. With JavaScript turned off, the default figures are shown.

Page filters (apply to the pipeline, identifier records and ledger; the date range also applies to the severity heatmap)

Assessed by
Severity
to

Showing all assessment sources and severities for findings discovered between November 1, 2025 and October 2, 2026.

DiscoveredTriaged
29,439 findingsCandidates
Triage by external security research firms
6,123 findingsReviewed by external security firms
5,674 findingsConfirmed valid92.7% true positives of 6,123
1,333 findingsReported to maintainers
Direct disclosure
4,824 findingsReported direct to maintainers by AnthropicMay contain false positives
DisclosedRemediated
6,157 findingsTotal reported to maintainers
5,103 findingsAcknowledged by maintainer
516 findingsPatched upstream
584 advisoriesCVEs and GHSAs assigned

Counts as of October 2, 2026

How these figures are produced

The statistics above reflect all bugs found by Claude Mythos Preview and other Claude models. They can also be filtered by severity under at least one of three assessment sources: Claude's own assessment, the assessment of the external security research firm that triaged the finding, or the project maintainer's assessment. Each source is defined in the glossary on the About page, and the filtered view states how many findings the selected sources have not assessed. These figures are designed to reflect our coordinated vulnerability disclosure process, which works approximately as follows. A glossary of the terms is available on the About page.

First, our models find candidate vulnerabilities, which we add to a list for human triage. This is the figure at the top. The count includes candidates from Mythos Preview, other Mythos-class models and other Claude models.

Then, in order to disclose a vulnerability to a maintainer, we take one of two steps.

Triage: We pass them to one of six external security research firms that we have engaged for this endeavor. The security research firms reproduce each issue, assess whether it is a real bug (and if so, assess how severe it is), and then write a report for confirmed bugs that will go to the project's maintainer. Importantly, there are many additional bugs that we or our security partners have investigated and confirmed are real but that we have not yet reported to maintainers, due to capacity limitations.

In our triage process, the "true positive rate" (the number of findings confirmed as valid, as a share of the number of findings manually reviewed) reflects how often the external security research firms determined that a finding Mythos Preview (and other Claude models) produced was a real vulnerability. This includes real bugs that we later discover have already been reported, and "won't fix" findings (the bug is real, but the maintainer is unlikely to address it, e.g. because it falls outside the project's threat model, or affects code that isn't typically reachable). We include these in the true positive rate because we're reliant on our security research partners (rather than maintainers) to tell us how many bugs they've confirmed, and it's only after the maintainers have received the report and assessed the vulnerability that we'll learn whether a vulnerability is one they plan to fix. For this reason, it's also possible that a vendor has marked a vulnerability as a true positive (or a false positive) in error. Given this, the number of "true positives" in the dashboard above should only be taken as one proxy for impact. Another, more reliable one is the number of patches created, though this is only a lagging indicator of progress, since patches take a long time to create.

Direct disclosure: Other vulnerabilities are disclosed to maintainers directly, without the same independent check. This also happens when maintainers specifically request that we provide them un-triaged findings.

Once bugs have either been triaged or directly disclosed, "Acknowledged by maintainer" counts all bugs whose reports maintainers have responded to. "Patched upstream" counts the reported vulnerabilities that maintainers have since created and released fixes for, whether or not they replied to the report, though this does not guarantee that those patches have been widely installed. Finally, "CVEs and GHSAs assigned" counts the CVE records and GitHub Security Advisories issued across all findings in the ledger, whether or not a patch has shipped (a finding may carry both). Some advisories are now public, and we list them out further down on this page. We leave whether to create a security advisory up to the discretion of maintainers.

See About for more information.

Anthropic, Coordinated vulnerability disclosure dashboard (opens Anthropic site in a new tab). The glossary and the About page are reproduced below in About & methodology.

04 · Severity agreement

Claude's severity vs external review

Claude vs external security research firm

Shown on Anthropic's dashboard
Firm-assessedClaude-assessedcriticalhighmediumlowcriticalClaude-assessed critical vs Firm-assessed critical: 116116Claude-assessed critical vs Firm-assessed high: 121121Claude-assessed critical vs Firm-assessed medium: 77Claude-assessed critical vs Firm-assessed low: 1515highClaude-assessed high vs Firm-assessed critical: 1414Claude-assessed high vs Firm-assessed high: 828828Claude-assessed high vs Firm-assessed medium: 2323Claude-assessed high vs Firm-assessed low: 1212mediumClaude-assessed medium vs Firm-assessed critical: 22Claude-assessed medium vs Firm-assessed high: 2525Claude-assessed medium vs Firm-assessed medium: 148148Claude-assessed medium vs Firm-assessed low: 22lowClaude-assessed low vs Firm-assessed critical: 33Claude-assessed low vs Firm-assessed high: 0Claude-assessed low vs Firm-assessed medium: 33Claude-assessed low vs Firm-assessed low: 1818
Claude-assessed (rows) against external security research firm-assessed (columns), n = 1337. 83.0% exact agreement, 97.1% within one band.
View as table
Claude-assessed against Firm-assessed
Claude ↓ / Firm-assessed →criticalhighmediumlow
critical116121715
high148282312
medium2251482
low30318

This graph compares Claude's initial severity assessments against the external security research firms' assessments, for those findings that have completed triage. Cells on the diagonal indicate agreement. The number assessed here represents the subset of vulnerabilities included on our disclosure ledger that were reviewed by our security partners, rather than disclosed by us directly.

Anthropic's severity assessments are produced before any maintainer input. Project maintainers often apply project-specific severity rules that Claude does not have access to at run time, so what one maintainer rates as critical another may rate as low. The external security research firms incorporate that context, which is why their assessments tend to be lower.

Anthropic, CVD dashboard (opens Anthropic site in a new tab)

Claude vs project maintainer

From payload.json · not charted on the source page
Maintainer-assessedClaude-assessedcriticalhighmediumlowcriticalClaude-assessed critical vs Maintainer-assessed critical: 33Claude-assessed critical vs Maintainer-assessed high: 1010Claude-assessed critical vs Maintainer-assessed medium: 99Claude-assessed critical vs Maintainer-assessed low: 11highClaude-assessed high vs Maintainer-assessed critical: 99Claude-assessed high vs Maintainer-assessed high: 6464Claude-assessed high vs Maintainer-assessed medium: 4545Claude-assessed high vs Maintainer-assessed low: 99mediumClaude-assessed medium vs Maintainer-assessed critical: 0Claude-assessed medium vs Maintainer-assessed high: 11Claude-assessed medium vs Maintainer-assessed medium: 66Claude-assessed medium vs Maintainer-assessed low: 22lowClaude-assessed low vs Maintainer-assessed critical: 0Claude-assessed low vs Maintainer-assessed high: 0Claude-assessed low vs Maintainer-assessed medium: 22Claude-assessed low vs Maintainer-assessed low: 22
Claude-assessed (rows) against maintainer-assessed (columns), n = 163, from severity_matrix.claude_vs_maintainer in Anthropic's payload.json. 46.0% exact agreement, 88.3% within one band (calculated by IntelliXBOM). This matrix is not filtered by the page filters.
View as table
Claude-assessed against Maintainer-assessed
Claude ↓ / Maintainer-assessed →criticalhighmediumlow
critical31091
high964459
medium0162
low0022

05 · Ledger insights

What the ledger contains

Breakdowns that IntelliXBOM calculated from Anthropic's published data files (revision 35). Anthropic does not publish these as separate figures. Each count comes straight from a field in the files, with no estimates and no weighting. These charts cover the whole ledger and are not affected by the page filters.

Ledger entries by disclosure stage

payload.json · tier_partition
  • Committed (hash and date only) discovered438 6.6%
  • Report sent sent1,054 16.0%
  • Acknowledged by maintainer acknowledged_by_maintainer4,868 73.8%
  • Revealed (disclosure window closed) revealed237 3.6%
All 6,597 ledger entries, by reveal_tier. The stage controls which fields the ledger publishes. A revealed entry shows its identifier, project and bug class. A sent or acknowledged entry shows its status and severity. A committed entry shows only its hash and commitment date.

Severity ratings published in the ledger

ledger.json · *_severity
Claude-assessed6,152 entries with a published rating
critical 315 high 1,285 medium 2,381 low 2,171 not published / not assessed 445
Firm-assessed1,341 entries with a published rating
critical 137 high 976 medium 181 low 47 not published / not assessed 5,256
Maintainer-assessed166 entries with a published rating
critical 13 high 76 medium 63 low 14 not published / not assessed 6,431
View as table
Severity ratings published in the ledger, by assessment source
SourcecriticalhighmediumlowNot published / not assessed
Claude-assessed3151,2852,3812,171445
Firm-assessed137976181475,256
Maintainer-assessed137663146,431
Ratings for each of the 6,597 ledger entries, by assessment source. A firm rating exists only for firm-reviewed findings, and a maintainer rating only when the maintainer has provided one.

Ledger entries by month committed

ledger.json · committed_at
  1. 7Feb '26
  2. 82Mar '26
  3. 252Apr '26
  4. 1,388May '26
  5. 12Jun '26
  6. 462Jul '26
  7. 3,812Aug '26
  8. 308Sep '26
  9. 274Oct '26
View as table
Ledger entries by month committed
MonthEntries
Feb 20267
Mar 202682
Apr 2026252
May 20261,388
Jun 202612
Jul 2026462
Aug 20263,812
Sep 2026308
Oct 2026274
All 6,597 entries by "Date committed" (UTC). Anthropic notes that this date comes from its records and can be earlier than the date the hash was computed or first listed.

Ledger entries by month discovered

ledger.json · discovered_on
  1. 2Nov '25
  2. 5Dec '25
  3. 2Jan '26
  4. 12Feb '26
  5. 509Mar '26
  6. 1,745Apr '26
  7. 2,424May '26
  8. 1,021Jun '26
  9. 163Jul '26
  10. 155Aug '26
  11. 121Sep '26
View as table
Ledger entries by month discovered
MonthEntries
Nov 20252
Dec 20255
Jan 20262
Feb 202612
Mar 2026509
Apr 20261,745
May 20262,424
Jun 20261,021
Jul 2026163
Aug 2026155
Sep 2026121
The 6,159 entries with a published discovery date (UTC). The discovery date is published once the report has been sent, and it drives the page's date filter.

Revealed findings by status

ledger.json · reveal_tier = revealed
  • disclosed14 5.9%
  • fixed218 92.0%
  • withdrawn3 1.3%
  • merged2 0.8%
The 237 entries whose disclosure window has closed, by status column.

Withdrawal and merge reasons

ledger.json · withdrawn_reason
  • mistake137
  • duplicate85
  • false_positive11
  • out_of_scope7
  • rejected_not_sec5
  • report_withdrawn3
The 248 entries that have a recorded reason, using the reason codes exactly as they appear in the ledger.

Revealed findings by bug class

ledger.json · bug_class
  • heap-buffer-overflow90
  • other26
  • stack-buffer-overflow24
  • use-after-free19
  • auth-bypass8
  • sql-injection7
  • denial-of-service6
  • path-traversal6
  • oob-write5
  • broken-access-control4
  • integer-overflow4
  • double-free3
  • privilege-escalation3
  • crypto-failure3
  • integer-underflow3
  • buffer-overflow2
  • rce2
  • open-redirect2
  • xss2
  • stack-overflow2
  • signature-bypass2
  • oob-read2
  • improper-cert-validation2
  • code-injection1
  • off-by-one1
  • logic-error1
  • deserialization1
  • idor1
  • global-buffer-overflow1
  • ssrf1
  • symlink-following1
  • type-confusion1
  • arbitrary-file-write1
The 237 revealed findings. Bug class is published only once a finding's disclosure window has closed.

Revealed findings by project

ledger.json · project
  • ffmpeg/ffmpeg14
  • libreoffice/core12
  • wolfssl/wolfssl12
  • freerdp/freerdp11
  • osgeo/gdal11
  • supabase/supabase11
  • supabase/auth9
  • wireshark/wireshark8
  • torvalds/linux6
  • opensc4
  • supabase/postgres4
  • c-blosc23
All 113 projects
  • cisco-talos/clamav3
  • graphicsmagick/graphicsmagick3
  • libjxl3
  • oisf/suricata3
  • selinux3
  • artifexsoftware/ghostpdl2
  • bytecodealliance/wasm-micro-runtime2
  • cesnet/libyang2
  • danbloomberg/leptonica2
  • dnsmasq2
  • duckdb2
  • freebsd/freebsd-src2
  • freetype/freetype2
  • joomla/joomla-cms2
  • kjur/jsrsasign2
  • libvips/libvips2
  • mastodon/mastodon2
  • nginx/nginx2
  • nss2
  • openssh/openssh-portable2
  • php/php-src2
  • rabbitmq-c2
  • rocketchat/rocket.chat2
  • tryghost/ghost2
  • twigphp/twig2
  • upx2
  • alembic1
  • apache/spark1
  • asterisk/asterisk1
  • ava-labs/libevm1
  • bearssl1
  • binutils1
  • cgif1
  • cloudflare/circl1
  • cloudfoundry/uaa1
  • craftcms/cms1
  • dhis2/dhis2-core1
  • exim/exim1
  • faad21
  • facebook/hermes1
  • firecracker-microvm/firecracker1
  • flex1
  • gitoxidelabs/gitoxide1
  • go-gitea/gitea1
  • gpac1
  • gpg/gnupg1
  • gpg/libgcrypt1
  • grok1
  • htslib1
  • hunspell1
  • imagemagick/imagemagick1
  • isc-projects/bind91
  • jetty/jetty.project1
  • jqlang/jq1
  • jsoncons1
  • junrar1
  • langchain-ai/deepagentsjs1
  • libarchive/libarchive1
  • libass/libass1
  • libexpat/libexpat1
  • libgit2/libgit21
  • libjpeg-turbo/libjpeg-turbo1
  • libmspub1
  • liboqs1
  • libredwg1
  • libssh2/libssh21
  • libtom/libtomcrypt1
  • lua/lua1
  • mapserver1
  • minio/minio1
  • mm2/little-cms1
  • moodle/moodle1
  • mpv-player/mpv1
  • ncurses1
  • nftables1
  • nomad1
  • open62541/open625411
  • openbabel1
  • opencontainers/runc1
  • openexr1
  • openmeterio/openmeter1
  • openmrs/openmrs-module-fhir21
  • openssl/openssl1
  • poppler1
  • postgres/postgres1
  • randombit/botan1
  • rdkit1
  • sctp/lksctp-tools1
  • sentinelone/purple-mcp1
  • simd1
  • syncthing/syncthing1
  • temporalio/temporal1
  • typo31
  • tz1
  • u-boot/u-boot1
  • unicorn1
  • universal-ctags/ctags1
  • util-linux/util-linux1
  • wabt1
  • webkit/webkit1
  • xdao1
113 projects have at least one revealed finding. The headline figure of 591 projects covers all disclosed findings, most of which are not yet revealed.

06 · Vulnerability records

Published CVE and GHSA records

94 CVE and 63 GHSA records that the assigning authority has published, for findings whose disclosure window has closed. Each record shows the project, bug class, severity, Anthropic finding identifier (linking to Anthropic's finding card) and title. Advisory links go to NVD or GitHub. Of the 584 identifiers issued in total, 332 are counted as published in Anthropic's payload (advisories_published).

CVEs 94

payload.json · cve_records

Common Vulnerabilities and Exposures records assigned to findings disclosed through this program. The records below are publicly available. Identifiers not listed belong to findings whose disclosure window has not yet closed, or have not yet been published by the assigning authority.

CVE-2026-13595 (opens in a new tab)
util-linux/util-linux · use-after-free · medium · ANT-2026-ZRDQDR79Heap-use-after-free in blkid_partition_get_start at partitions.c:1447 via nested BSD disklabel in DOS partition table
Discovered 2026-03-20 · Revealed 2026-08-17
CVE-2026-27654 (opens in a new tab)
nginx/nginx · heap-buffer-overflow · high · ANT-2026-HY56VRSBHeap buffer overflow in ngx_http_dav_copy_move_handler at ngx_http_dav_module.c:703 via short Destination header with alias directive
Discovered 2026-03-20 · Revealed 2026-05-20
CVE-2026-41401 (opens in a new tab)
cesnet/libyang · use-after-free · medium · ANT-2026-TZQ1KH7EHeap use-after-free write in metadata list management during XML data parsing due to incorrect list head pointer update
Discovered 2026-03-29 · Revealed 2026-05-20
CVE-2026-45700 (opens in a new tab)
freerdp/freerdp · heap-buffer-overflow · critical · ANT-2026-HN9XZXJ9heap-buffer-overflow write (attacker-controlled offset, partially-controlled data via rle delta values; up to ~15kb overwrite past ptempdata with these parameters, further with larger nxdst) in planar.c:472
Discovered 2026-03-24 · Revealed 2026-05-20
CVE-2026-63559 (opens in a new tab)
open62541/open62541 · integer-overflow · high · ANT-2026-PJV7Z0ARInteger overflow in variant dimension validation allowing wild-address write via arrayDimensions product overflow
Discovered 2026-03-29 · Revealed 2026-08-17
CVE-2026-6479 (opens in a new tab)
postgres/postgres · denial-of-service · high · ANT-2026-CJQWKW82Pre-auth unbounded recursion in ProcessStartupPacket: alternating SSL/GSS negotiation requests cause infinite recursion when both are rejected. ssl_done/gss_done flags oscillate (true,false)->(false,true) endlessly. No check_stack_depth. Pre-authentication.
Discovered 2026-04-02 · Revealed 2026-07-21
CVE-2026-65423 (opens in a new tab)
open62541/open62541 · integer-overflow · high · ANT-2026-PJV7Z0ARInteger overflow in variant dimension validation allowing wild-address write via arrayDimensions product overflow
Discovered 2026-03-29 · Revealed 2026-08-17
CVE-2026-6772 (opens in a new tab)
nss · heap-buffer-overflow · high · ANT-2026-1ZNMP148Off-by-one heap buffer overflow in TLS extension negotiation due to SSL_MAX_EXTENSIONS (22) being too small for 23 extensions
Discovered 2026-03-29 · Revealed 2026-08-17

GHSAs 63

payload.json · ghsa_records

GitHub Security Advisory records assigned to findings disclosed through this program. The records below are publicly available. Identifiers not listed belong to findings whose disclosure window has not yet closed, or have not yet been published by the assigning authority.

GHSA-hwfh-mh4f-m67f (opens in a new tab)
postgres/postgres · denial-of-service · high · ANT-2026-CJQWKW82Pre-auth unbounded recursion in ProcessStartupPacket: alternating SSL/GSS negotiation requests cause infinite recursion when both are rejected. ssl_done/gss_done flags oscillate (true,false)->(false,true) endlessly. No check_stack_depth. Pre-authentication.
Discovered 2026-04-02 · Revealed 2026-07-21
GHSA-mpxh-8fq3-x8mh (opens in a new tab)
freerdp/freerdp · heap-buffer-overflow · critical · ANT-2026-H97FY6C8Heap-buffer-overflow in cliprdr_main.c:547
freerdp/freerdp · heap-buffer-overflow · critical · ANT-2026-HN9XZXJ9heap-buffer-overflow write (attacker-controlled offset, partially-controlled data via rle delta values; up to ~15kb overwrite past ptempdata with these parameters, further with larger nxdst) in planar.c:472
freerdp/freerdp · heap-buffer-overflow · critical · ANT-2026-RXYVE4DZHeap-buffer-overflow in sanitizer_common_interceptors.inc:827
Discovered 2026-03-24 · Revealed 2026-05-20
GHSA-mvpx-xj7r-3p3r (opens in a new tab)
freerdp/freerdp · heap-buffer-overflow · critical · ANT-2026-H97FY6C8Heap-buffer-overflow in cliprdr_main.c:547
freerdp/freerdp · heap-buffer-overflow · critical · ANT-2026-HN9XZXJ9heap-buffer-overflow write (attacker-controlled offset, partially-controlled data via rle delta values; up to ~15kb overwrite past ptempdata with these parameters, further with larger nxdst) in planar.c:472
freerdp/freerdp · heap-buffer-overflow · critical · ANT-2026-RXYVE4DZHeap-buffer-overflow in sanitizer_common_interceptors.inc:827
Discovered 2026-03-24 · Revealed 2026-05-20
GHSA-p6r2-4hgm-m6ff (opens in a new tab)
freerdp/freerdp · heap-buffer-overflow · critical · ANT-2026-H97FY6C8Heap-buffer-overflow in cliprdr_main.c:547
freerdp/freerdp · heap-buffer-overflow · critical · ANT-2026-HN9XZXJ9heap-buffer-overflow write (attacker-controlled offset, partially-controlled data via rle delta values; up to ~15kb overwrite past ptempdata with these parameters, further with larger nxdst) in planar.c:472
freerdp/freerdp · heap-buffer-overflow · critical · ANT-2026-RXYVE4DZHeap-buffer-overflow in sanitizer_common_interceptors.inc:827
Discovered 2026-03-24 · Revealed 2026-05-20

07 · Disclosure ledger

Vulnerability disclosure ledger

Each entry is a SHA-3-512 hash of one finding's details. "Date committed" comes from our records. It can be earlier than the date the hash was computed or first listed here. Each ledger entry shows more detail as it progresses through disclosure: before the maintainer has been notified, only the commitment hash and the commitment date are published; once the report has been sent, the status and the severity assessments are shown and the discovery date is published (it drives the date filter); and the identifier, project, and bug class are revealed only when the disclosure window closes. A commitment that is withdrawn at any stage keeps its hash and commitment date and is marked withdrawn in the status column; a commitment withdrawn before the finding was revealed is also struck through in the table.

Anthropic, Disclosure ledger (opens Anthropic site in a new tab)

Matching6,597of 6,597 entries
disclosed6,157
fixed218
pre disclosure195
withdrawn246
merged2

The "disclosed" tile counts every entry whose report has been sent, so it includes fixed entries and entries withdrawn after reveal. This matches how Anthropic's ledger counts it.

Disclosure ledger: date committed, hash or identifier, project, bug class, severity assessments and status. Select a row's details button to see every published field.
Severity assessments
2026-10-02425c35d5b403485da0bd…WithheldWithheldClaude: mediumdisclosed
2026-10-026e35454ade4c90f28cc5…WithheldWithheldClaude: mediumdisclosed
2026-10-02ac8c9b7be18e2994f42d…WithheldWithheldClaude: mediumdisclosed
2026-10-02d374165be765d159432f…WithheldWithheldClaude: mediumdisclosed
2026-10-020aa4a1d9f1155fabb3f4…WithheldWithheldClaude: lowdisclosed
2026-10-025b928ab1e814957714b3…WithheldWithheldClaude: mediumdisclosed
2026-10-0260b187740e40f297e179…WithheldWithheldClaude: criticaldisclosed
2026-10-0210864ef6de77876f6a1f…WithheldWithheldClaude: mediumdisclosed
2026-10-02442eb7982813893880c3…WithheldWithheldClaude: mediumdisclosed
2026-10-027fd14ea02d40cef3f435…WithheldWithheldClaude: highdisclosed
2026-10-025b38fdefae40ed1d7857…WithheldWithheldClaude: mediumdisclosed
2026-10-028f10479a05c41bca1d34…WithheldWithheldClaude: highdisclosed
2026-10-02999c9f7f359013a42ce9…WithheldWithheldClaude: mediumdisclosed
2026-10-028f8d854b428a7947f099…WithheldWithheldClaude: mediumdisclosed
2026-10-02ded647e8e0587edcd44e…WithheldWithheldClaude: mediumdisclosed
2026-10-02dcaeabfd36e7af88c7fd…WithheldWithheldClaude: highdisclosed
2026-10-02100519bc750acaac63ea…WithheldWithheldClaude: mediumdisclosed
2026-10-02470c01c005ff35436475…WithheldWithheldClaude: mediumdisclosed
2026-10-0247da586fc4488c1d384f…WithheldWithheldClaude: mediumdisclosed
2026-10-02af0b7587b917aee5faea…WithheldWithheldClaude: highFirm: lowdisclosed
2026-10-02840d38765b32fb734179…WithheldWithheldClaude: mediumdisclosed
2026-10-02a223d1b847987d769510…WithheldWithheldClaude: highdisclosed
2026-10-020b4c98d39abb85e38342…WithheldWithheldClaude: mediumdisclosed
2026-10-0231db2aa4e6a3aefc755a…WithheldWithheldClaude: mediumdisclosed
2026-10-021902f80229aac596df22…WithheldWithheldClaude: mediumdisclosed
Showing 1–25 of 6,597 / 264

Select a row to expand it and see every field Anthropic publishes for the entry: full hash, discovery, reveal and patch dates, CVE and GHSA identifiers, corrections, withdrawal reason and date, merge target and triage flags. Fields Anthropic has not yet published are marked as withheld. Full data: ledger.json (opens Anthropic site in a new tab) · payload.json (opens Anthropic site in a new tab).

08 · About & methodology

About Anthropic's CVD programme and this data

Reproduced from Anthropic's About this dashboard (opens Anthropic site in a new tab) page, with the provenance notes from the dashboard and ledger.

About this dashboard

Anthropic uses Claude to discover security vulnerabilities in widely used open-source software. When a finding is validated, the affected project's maintainers are notified privately and given time to issue a fix before details are made public consistent with the timelines provided in our Coordinated Vulnerability Disclosure (opens Anthropic site in a new tab) policy. This site summarizes the program's progress as of October 2, 2026.

External security research firm partners

The following are the external security research firms that work with us to triage Claude's vulnerability findings and notify project maintainers.

Glossary

Glossary of terms used by Anthropic's CVD dashboard
TermDefinition
CandidatesEvery distinct crash or vulnerability hypothesis that Claude produced across the program, before any triage.
True positive rateThe share of firm-reviewed findings confirmed as real, including duplicates and "won't fix" findings.
Total reported to maintainersA finding whose report has been sent to the project maintainer.
Acknowledged by maintainerThe maintainer has responded to the report. The count of these findings reflects the fact the OSS maintainers are experiencing a higher volume of inbound security findings. Our teams reach out to maintainers based on the severity of the findings and existing maintainer volume.
Patched upstreamA patch has landed after the report was sent.
CVEs and GHSAs assignedA CVE or GHSA identifier assigned to a finding. Identifiers themselves are listed once the finding's disclosure window has closed and the assigning authority has published the record.
Disclosure windowSee Anthropic's Coordinated Vulnerability Disclosure policy (opens Anthropic site in a new tab).
Commitment hashA SHA-3-512 hash of the finding's details, which we call the preimage.
LedgerThe record of commitment hashes and their reveal state. Hashes are never removed, and once a finding has been revealed, its identifier, project, bug class, advisories, severities and dates are never removed; a finding may later be marked withdrawn or merged, with the date and, where recorded, the reason. An advisory identifier published in error stays visible as a struck-through correction rather than being removed. A patch date published in error stays on the finding's timeline, worded as a correction, and moves from patched_at to corrected_patched_at in ledger.json. A finding withdrawn while it remains revealed keeps its full card; only when a finding's reveal is cleared after publication are its report text and preimage withheld.
WithdrawnA commitment that is no longer active. For example, the finding was retracted or duplicated a known issue, or an edit to its details gave it a new hash and entry. Before the finding is revealed it shows only the hash and commitment date; after it has been revealed it keeps its identifier and advisories and is marked withdrawn with the date and reason.
MergedA commitment whose finding was consolidated into another finding; the entry keeps its identifier and links to the surviving finding.
SeverityThe assessor's rating of impact (critical, high, medium, low).
Claude-assessed severityThe severity Claude assigned when it first analyzed the finding, recorded on the canonical report before any external review.
Firm-assessed severityThe severity assigned by an external security research firm during triage. It exists only for findings a firm has reviewed.
Maintainer-assessed severityThe severity assigned by the project maintainer, typically through a published security advisory. It exists only when the maintainer has provided one.
Bug classThe vulnerability category.

Verifying a commitment

The commitment hash is the SHA-3-512 digest of a canonical JSON document. The document has sorted keys, no whitespace between tokens, and is encoded as UTF-8. It contains the finding identifier, project, creation time, title, bug class, target commit, location, discovery time, Claude's and the security research firm's severity assessments, the description, technical details, reproduction steps, and the SHA-256 of the proof-of-concept artifact. Fields not known when the hash was computed are recorded as null. The preimage records each assessment as of the time the hash was computed; if the external security research firm later revises its severity, the card shows the current value marked as revised alongside the sealed one. To verify, download the preimage JSON from the finding card and confirm that its SHA-3-512 digest matches the commitment hash published on the ledger.

Each ledger entry shows more detail as it progresses through disclosure: before the maintainer has been notified, only the commitment hash and the commitment date are published; once the report has been sent, the status and the severity assessments are shown and the discovery date is published (it drives the date filter); and the identifier, project, and bug class are revealed only when the disclosure window closes. A commitment that is withdrawn at any stage keeps its hash and commitment date and is marked withdrawn in the status column; a commitment withdrawn before the finding was revealed is also struck through in the table.

Finding cards

Once a finding's disclosure window closes, its identifier in the ledger links to a finding card. A card shows the project, bug class, and severity. When the report body carries substantive content, the card also shows Anthropic's analysis of the finding. Every card links to any assigned advisory that the assigning authority has published, and shows the commitment hash. A card for a finding that remains published also shows the preimage JSON, so that the published card can be verified against the ledger entry that committed to it. A finding withdrawn while it remains revealed keeps its full card, report text and preimage included, marked as withdrawn after publication. Only a finding whose reveal was cleared after publication has its card replaced by a page that keeps the hash and identifiers but withholds the report text and the preimage, because the preimage is the withdrawn report.

On this page, every Anthropic finding identifier (ANT-…) links to its finding card on red.anthropic.com.

Changes between updates

The August 26, 2026 update showed dates in Pacific Time. They are now in UTC, so some are one day later.

Up to the August 26, 2026 update, finding cards listed "Reported to tracker". They now list "Discovered or logged" instead, and its date can be earlier.

Provenance

This snapshot was generated on 2026-10-02 19:47 UTC. The manifest hash below is the SHA-3-512 hash of the structured payload and is republished with every dated snapshot so any figure on this page can be verified against the machine-readable record.

Revision
35
Checksum (manifest SHA-3-512)
1fca6b3bafbdab0c2a55896e88c547016e90b28c554dc0b051895fc5639b0e5160b07598ccb6d2dcbfb9277b09a99ea81b4a4ba49cf36796a76fa7b6d97888f9
Snapshot generated
2026-10-02 19:47 UTC
Dates and times
UTC
Published by
Anthropic Frontier Red Team

From Anthropic's page footer: "Dates and times are in UTC" and "Archived snapshots remain available at their dated paths so any figure can be verified against the page that was live on that date." See the archive (opens Anthropic site in a new tab).

Severity definitions used by the filters

Claude-assessed
The severity Claude assigned when it first analyzed the finding, recorded on the canonical report before any external review.
Firm-assessed
The severity assigned by an external security research firm during triage. It exists only for findings a firm has reviewed.
Maintainer-assessed
The severity assigned by the project maintainer, typically through a published security advisory. It exists only when the maintainer has provided one.

The page filters work the same way as Anthropic's. A finding is counted when it was discovered inside the selected date range and at least one selected source rates it at one of the selected levels. Each finding is counted only once. When you narrow the sources, a line under the filters reports how many reported findings the selected sources have not assessed.

09 · Source

Source & attribution

Data presented on this page is sourced from Anthropic's publicly available Coordinated Vulnerability Disclosure resources. The figures, records, ledger entries, dates, severities and statuses come from Anthropic's snapshot revision 35, last updated 2026-10-02 19:47 UTC, which IntelliXBOM retrieved on October 7, 2026. Explanatory text marked as quoted is Anthropic's own wording. IntelliXBOM rearranged the information and added the derived breakdowns in Ledger insights, each labelled with its source field. IntelliXBOM has not changed any value, date, classification or severity.

Anthropic updates its dashboard periodically. If a figure here differs from Anthropic's live page, Anthropic's page takes precedence. IntelliXBOM is not affiliated with Anthropic. The names "Anthropic" and "Claude" are used only to identify the source of the data.