The curl Project Uses AISLE to Find and Fix Vulnerabilities in Code Installed on 20B+ Devices

AISLE and curl customer story artwork
All customer stories

The curl project needed to secure its nearly-ubiquitous software, which runs on over 20 billion devices, so it chose AISLE. Now curl’s lean team uses AISLE to find and fix vulnerabilities in its codebase, uncovering dozens of issues in one of the world’s most mature, rigorously audited libraries. In the words of curl founder and lead developer Daniel Stenberg, “AISLE is awesome.”

Key Results

  1. Dozens of software vulnerabilities in curl and libcurl found and fixed using AISLE

  2. 17 CVEs in curl discovered by AISLE, more than triple that of any other AI security company

  3. The curl project can keep its code secure without adding headcount

In late 2025, the curl project, which develops and secures vital open-source libraries installed on over 20 billion devices, closed its paid bug bounty because its lean team had become overwhelmed by a flood of low-quality, AI-generated submissions. But there was a diamond in the rough of AI findings. According to curl founder and lead developer Daniel Stenberg, "a new breed of analyzer" had emerged.

In the months before the curl project retired the paid bounty, 24 curl pull requests were attributed to AISLE and five security issues were assigned CVEs, for a total of 29 valid findings within several months. The curl project then started using AISLE to find and fix vulnerabilities. As Stenberg says, "AISLE is awesome."

"AISLE is awesome." — social post by Daniel Stenberg, curl founder

Safeguarding Vital Software Infrastructure With AISLE

The curl project develops and secures its nearly ubiquitous command line tool with a full-time team of one and input from the volunteer developers of the open-source community. As machine-generated code analysis strained the incentive systems that make open source possible, the curl project was challenged to accelerate their analysis and remediation workflows.

Stenberg was initially skeptical of the role AI could play in this effort, but he noted that "a new breed of analyzer" had emerged. For instance, AISLE's AI found issues including a QUIC pinned-public-key bypass, a wcurl path traversal, and two additional CVEs in the wolfSSH backend. Based on these results, as well as a solid collaborative relationship with the AISLE team, the curl project started using AISLE to find and propose fixes for vulnerabilities in February 2026.

"AISLE has a powerful analyzer that highlights code areas that need more attention in ways the old generation of code tools have not been able to." — Daniel Stenberg, founder and lead developer of curl

Putting AISLE to the Test

On August 24th, curl founder Daniel Stenberg said the curl project had only three pending CVEs to release, with no findings reported by Mythos, Zeropath, or Codex Security. AISLE then analyzed the full codebase to see if its AI, which is constantly being improved on the basis of internal research, could find anything else. 

One day later:

a screenshot of Daniel Stenberg writing Mythos: 0 Aisle: 29

Within a few days, the curl project had assigned CVE-IDs for 6 of the 29 issues that AISLE found, with the rest deemed valid, low-level bugs. Only one of the findings was ruled a false positive. 

Interestingly, Greg Kroah-Hartman, the Linux Foundation Fellow responsible for the Linux kernel stable releases, reported similar results from AISLE:

Greg K-H says Aisle is doing something differently, wow

When the curl project used Mythos to analyze its codebase in June 2026, Stenberg wrote that it found one low-severity CVE. By contrast, 17 curl CVEs have been attributed to AISLE as of September 2026, with the majority coming after June. 

This result is further confirmation of our thesis that cybersecurity capability is jagged. Rather than being tied to a single frontier model, vulnerability detection is a multi-phase process best solved by a multi-agent system like AISLE’s.

Empowering Security Organizations Using AISLE

The curl project aims to continue using AISLE to both secure its existing code and verify that it does not ship new vulnerabilities in upcoming releases. As Stenberg says: “My experience from working with AISLE on and off for many months now is nothing but good. Skilled, professional engineers without any bureaucracy. They know their stuff, and they've been very good at listening in and adjusting for our needs and wants.”

Customers

More customer stories

CTA background

Point AISLE at your codebase.
See what your tools missed.

Run a structured proof of value in your environment.

Talk to Us

Available to qualified enterprise security teams