AISLE Discovered Six curl CVEs After OpenAI and Anthropic Found Zero

Author

Stanislav Fort

Published

Six Vulnerabilities in curl After Frontier AI Labs Came Back Empty hero image

See what AISLE can find and fix autonomously in your own code.

Sovereign AI CybersecurityTalk to Us

AISLE discovered six curl CVEs within days of OpenAI Codex Security and Anthropic Mythos reporting zero findings in curl, software deployed across more than 20 billion instances worldwide.

On August 24, 2026, curl founder Daniel Stenberg wrote that only three CVEs were pending for the next release. After using frontier AI cybersecurity systems to analyze curl, he added:

"[Anthropic] Mythos says it can’t find any more. ... [OpenAI] Codex security shows an empty list."

Mastodon post by curl founder Daniel Stenberg nine days before release, reporting three pending CVEs and zero additional findings from Mythos, Zeropath, and Codex Security.

Daniel Stenberg’s August 24 post: the public, timestamped zero-result that preceded AISLE’s findings.

Daniel had recently documented Mythos's results on curl, one of the world's most heavily audited codebases which is deployed everywhere from smart fridges to spacecraft. We then ran AISLE's autonomous AI system against curl.

The next day, before the review process was complete, Daniel posted: "Mythos: 0
Aisle: 29".

Daniel Stenberg’s comparison showing Mythos with zero findings and AISLE with 29 reports.

The next day, Daniel posted the first public comparison: Mythos 0, AISLE 29 reports.

Of the 29 AISLE reports, 6 were reviewed within days by curl’s security team, which deemed them serious enough to merit a public CVE designation for curl 8.22.0, which has just been released. They are:

  1. CVE-2026-80229: OpenSSL provider use-after-free
  2. CVE-2026-80230: OpenSSL pinning bypass
  3. CVE-2026-80231: native CA store connection reuse
  4. CVE-2026-80255: secure attribute bypass with tab
  5. CVE-2026-82208: wolfSSL CA-cache hit overrides callback
  6. CVE-2026-82209: domain-scoped public-suffix cookie

All six are rated Low severity. This profile is consistent with curl's exceptional engineering maturity: the vulnerabilities that remain tend to hide in narrow configurations and subtle interactions, limiting their practical impact. All six were fixed in curl 8.22.0 and officially credit Stanislav Fort (from AISLE) as the reporter. Three were reported on August 24, two on August 26, and one on August 27, 2026.

Unlike typical evaluations of AI for cybersecurity, this was not a capture-the-flag challenge or a benchmark with known answers that might already appear in model training data. AISLE analyzed current production code, and curl’s maintainers, not us, decided both whether each finding was real and whether it warranted a CVE.

Because Daniel Stenberg published the frontier AI systems’ zero-result before we ran AISLE, the comparison had an unusually clean property in that the baseline was public and timestamped before our result existed. CVEs are imperfect markers, but they provide unusually strong external validation for zero-day discovery, since each is a previously unknown flaw in production code, reproduced and accepted by domain experts, then fixed for deployed users.

By August 28, curl’s pending CVE count had risen from three to ten. Six of those ten came from AISLE, following the publicly reported zero-result from Anthropic's and OpenAI's frontier AI systems.

The pattern may not be limited to curl. Greg Kroah-Hartman, the longtime maintainer of Linux stable releases, responded to Daniel’s post saying: "I'm seeing the same for Linux as well. No idea what Aisle is doing differently, but wow..."

Linux stable maintainer Greg Kroah-Hartman says he is seeing the same pattern from AISLE in Linux.

Greg Kroah-Hartman reported seeing the same pattern in the Linux kernel.

This is another in a growing series of head-to-head results supporting our System over Model thesis: specialized AI systems can compete with and outperform systems from frontier AI labs at real-world zero-day discovery.

On curl, the result was six to zero.


See What AISLE Finds in Your Code

The same discovery engine that powered our findings in curl and Linux is available as a one-time AI code audit: AISLE Snapshot. See what our AI finds in your code, wherever it lives: air-gapped, on-prem, or in the cloud. Get your Snapshot.

Keep reading

More from AISLE

ResearchAISLE Discovers 6 High and Critical CVEs in FFmpegAISLE's AI-native engine found six high and critical CVEs in FFmpeg, including a 9.8 remote heap overflow and a stack overflow that survived 19 years.AISLE Research Team August 27, 2026ResearchAttackers Are Using AI to Find Vulnerabilities in Your Code. Your SAST Was Never Even Looking for ThemCan AI-native code analysis replace SAST, or is it just a complement. Here's what data from real-world results shows.Ondrej VlcekAugust 12, 2026ResearchAISLE Finds 21 Security Issues in FFmpeg, Including 6 New CVEsAISLE uncovered 21 issues in FFmpeg, including 6 new CVEs spanning code execution and out-of-bounds reads. All patched, with commit links inside.AISLE Research Team August 5, 2026ResearchAISLE Discovers a One-Click RCE Vulnerability in Cursor, VS Code, and Google AntigravityLearn how our AI found a one-click RCE vulnerability in 3 code editors: Cursor, VS Code, and Google Antigravity.Stanislav FortJuly 31, 2026ResearchThe Model That Fixes Your Code Might Hack the Linux KernelLearn how easy it is to trojanize a model, and what defenders can do to protect their supply chains from this emerging threat.Patrik MadaJuly 28, 2026PerspectivesThe Economics of Security Vulnerabilities: Why Discovery Is Not CommoditizingIf discovery is cheap, why are people willing to pay more for exploits than ever before? Here's what the market for exploits shows.Ondrej VlcekJuly 23, 2026ResearchAISLE Finds 8 CVEs Across MySQL, MariaDB, and PostgreSQLLearn how AISLE found 8 CVEs in critical databases using autonomous, AI-native analysis and verification.AISLE Research Team July 7, 2026ResearchAISLE Discovers 6 New CVEs in curl, Including the Oldest Issue Ever ReportedAISLE's analyzer discovered 6 new CVEs in curl, more than 2x the nearest AI security platform and including the oldest security issue in the project.AISLE Research Team June 24, 2026