AISLE Discovered 5 CVEs in curl. Now curl Uses Our AI to Secure Its Code

Author

AISLE Research Team

Published

AISLE curl CVE findings and partnership

See what AISLE can find and fix autonomously in your own code.

Sovereign AI CybersecurityTalk to Us

AI-generated slop buried maintainers in low-quality reports, but AISLE’s autonomous analysis uncovered real vulnerabilities.

In late 2025, the curl project closed its paid bug bounty program after 7 years, 81 discoveries, and over $90,000 in rewards. Its lean team had become overwhelmed by a flood of low-quality, AI-generated submissions. It was, as curl’s creator Daniel Stenberg put it, “death by a thousand slops.”

But there was a diamond in the rough of AI findings. According to Stenberg, “a new breed of analyzer” had emerged. In the months before the curl project retired the paid bounty, 24 curl pull requests were attributed to AISLE’s AI platform and five security issues were assigned CVEs, for a total of 29 valid findings.

So even though AI killed curl’s paid bug bounty, curl maintainers have been using AISLE to proactively spot and fix vulnerabilities since early February. And we now have an interesting measurement of its performance: Mythos.

What AISLE Discovered

In total, AISLE discovered five CVEs in curl. These are:

When we noticed that the AISLE platform had flagged an issue with the wolfSSH backend, we trained it on wolfSSH and uncovered two additional CVEs there:

Raising the Ceiling

Even as mediocre AI reports made it difficult for curl’s maintainers to make their way through submissions, high-quality systems like AISLE’s discovered dozens of valid security issues. As our co-founder Stanislav Fort notes in LessWrong,

This is a really clear example of a very common bifurcation of the top of a distribution from its median. Mass adoption collapsed the median quality (“slop” killed the bug bounty = a very viral story for people who assume that AI is bad at things a priori), but simultaneously raised the ceiling (we found many real vulnerabilities that the curl team valued enough to patch, assign CVEs to, and pay bounties for).

AI resists generalization. Yes, it shuttered the bug bounty, but it also made it obsolete. Though curl is no longer rewarding outside researchers for discovering vulnerabilities, it is using AISLE internally to achieve the same goal: thorough, continuous assessment.

Mythos Weighs In

When Anthropic announced project Glasswing in April 2026, it committed to making its cybersecurity model, Mythos, available to select open source projects. In May, Stenberg wrote that Mythos had scanned curl’s git repository and its master branch on a recent commit, with 176,000 lines of C code.

After he reviewed its report, he concluded that Mythos had found one issue deserving of CVE designation. It was a low-severity issue. In addition, there were a number of bugs currently being reviewed by the curl team.

Following AISLE’s discoveries in the April 2026 releases of OpenSSL and FreeBSD, this result is further confirmation of our thesis that cybersecurity capability is jagged. Rather than being tied to a single frontier model, cyber reasoning is a multi-phase process best solved by a multi-agent system. And for enduring results, that system must do more than analyze: it must triage, remediate, and validate at machine speed.

Safeguarding the Software Foundations of Modern Civilization

As machine-generated code strains the incentive systems that make open source possible, we believe AISLE can even the playing field. That’s why we’re excited to be providing it to the curl project so they can fight fire with fire.

Curious to see what AISLE can do for your organization? Reach out to us.

Keep reading

More from AISLE

FeaturedResearchAISLE Discovered Six curl CVEs After OpenAI and Anthropic Found ZeroAfter frontier AI systems came up empty, AISLE surfaced six CVEs in curl, one of the world's most audited codebases. Its maintainers patched all six.Stanislav FortSeptember 2, 2026ResearchAISLE Discovers 6 High and Critical CVEs in FFmpegAISLE's AI-native engine found six high and critical CVEs in FFmpeg, including a 9.8 remote heap overflow and a stack overflow that survived 19 years.AISLE Research Team August 27, 2026ResearchAttackers Are Using AI to Find Vulnerabilities in Your Code. Your SAST Was Never Even Looking for ThemCan AI-native code analysis replace SAST, or is it just a complement. Here's what data from real-world results shows.Ondrej VlcekAugust 12, 2026ResearchAISLE Finds 21 Security Issues in FFmpeg, Including 6 New CVEsAISLE uncovered 21 issues in FFmpeg, including 6 new CVEs spanning code execution and out-of-bounds reads. All patched, with commit links inside.AISLE Research Team August 5, 2026ResearchAISLE Discovers a One-Click RCE Vulnerability in Cursor, VS Code, and Google AntigravityLearn how our AI found a one-click RCE vulnerability in 3 code editors: Cursor, VS Code, and Google Antigravity.Stanislav FortJuly 31, 2026ResearchThe Model That Fixes Your Code Might Hack the Linux KernelLearn how easy it is to trojanize a model, and what defenders can do to protect their supply chains from this emerging threat.Patrik MadaJuly 28, 2026PerspectivesThe Economics of Security Vulnerabilities: Why Discovery Is Not CommoditizingIf discovery is cheap, why are people willing to pay more for exploits than ever before? Here's what the market for exploits shows.Ondrej VlcekJuly 23, 2026ResearchAISLE Finds 8 CVEs Across MySQL, MariaDB, and PostgreSQLLearn how AISLE found 8 CVEs in critical databases using autonomous, AI-native analysis and verification.AISLE Research Team July 7, 2026ResearchAISLE Discovers 6 New CVEs in curl, Including the Oldest Issue Ever ReportedAISLE's analyzer discovered 6 new CVEs in curl, more than 2x the nearest AI security platform and including the oldest security issue in the project.AISLE Research Team June 24, 2026