https://github.com/laie/WorldsFirstSha2Vulnerability Work by a random dude who pretends to find infinite collision so bad that he can't publish it. No math. No explanation. The code is a mix of single letter variables with hardly any comment. Thank you, I'll pass.
I'd say that counts as a vulnerability. It doesn't mean sha256 is broken, but it's a vulnerability.
EDIT: All of this modulo a rigged sha256.py, of course