The curl Project Uses AISLE to Find and Fix Vulnerabilities in Code Installed on 20B+ Devices

The curl project needed to secure its nearly-ubiquitous software, which runs on over 20 billion devices, so it chose AISLE. Now curl’s lean team uses AISLE to find and fix vulnerabilities in its codebase, uncovering dozens of issues in one of the world’s most mature, rigorously audited libraries. In the words of curl founder and lead developer Daniel Stenberg, “AISLE is awesome.”
Key Results
Dozens of software vulnerabilities in curl and libcurl found and fixed using AISLE
17 CVEs in curl discovered by AISLE, more than triple that of any other AI security company
The curl project can keep its code secure without adding headcount
In late 2025, the curl project, which develops and secures vital open-source libraries installed on over 20 billion devices, closed its paid bug bounty because its lean team had become overwhelmed by a flood of low-quality, AI-generated submissions. But there was a diamond in the rough of AI findings. According to curl founder and lead developer Daniel Stenberg, "a new breed of analyzer" had emerged.
In the months before the curl project retired the paid bounty, 24 curl pull requests were attributed to AISLE and five security issues were assigned CVEs, for a total of 29 valid findings within several months. The curl project then started using AISLE to find and fix vulnerabilities. As Stenberg says, "AISLE is awesome."

Safeguarding Vital Software Infrastructure With AISLE
The curl project develops and secures its nearly ubiquitous command line tool with a full-time team of one and input from the volunteer developers of the open-source community. As machine-generated code analysis strained the incentive systems that make open source possible, the curl project was challenged to accelerate their analysis and remediation workflows.
Stenberg was initially skeptical of the role AI could play in this effort, but he noted that "a new breed of analyzer" had emerged. For instance, AISLE's AI found issues including a QUIC pinned-public-key bypass, a wcurl path traversal, and two additional CVEs in the wolfSSH backend. Based on these results, as well as a solid collaborative relationship with the AISLE team, the curl project started using AISLE to find and propose fixes for vulnerabilities in February 2026.
"AISLE has a powerful analyzer that highlights code areas that need more attention in ways the old generation of code tools have not been able to." — Daniel Stenberg, founder and lead developer of curl
Putting AISLE to the Test
On August 24th, curl founder Daniel Stenberg said the curl project had only three pending CVEs to release, with no findings reported by Mythos, Zeropath, or Codex Security. AISLE then analyzed the full codebase to see if its AI, which is constantly being improved on the basis of internal research, could find anything else.
One day later:

Within a few days, the curl project had assigned CVE-IDs for 6 of the 29 issues that AISLE found, with the rest deemed valid, low-level bugs. Only one of the findings was ruled a false positive.
Interestingly, Greg Kroah-Hartman, the Linux Foundation Fellow responsible for the Linux kernel stable releases, reported similar results from AISLE:

When the curl project used Mythos to analyze its codebase in June 2026, Stenberg wrote that it found one low-severity CVE. By contrast, 17 curl CVEs have been attributed to AISLE as of September 2026, with the majority coming after June.
This result is further confirmation of our thesis that cybersecurity capability is jagged. Rather than being tied to a single frontier model, vulnerability detection is a multi-phase process best solved by a multi-agent system like AISLE’s.
Empowering Security Organizations Using AISLE
The curl project aims to continue using AISLE to both secure its existing code and verify that it does not ship new vulnerabilities in upcoming releases. As Stenberg says: “My experience from working with AISLE on and off for many months now is nothing but good. Skilled, professional engineers without any bureaucracy. They know their stuff, and they've been very good at listening in and adjusting for our needs and wants.”



