AISLE Discovered Six curl CVEs After OpenAI and Anthropic Found Zero
Author
Stanislav Fort
Date Published

AISLE discovered six curl CVEs within days of OpenAI Codex Security and Anthropic Mythos reporting zero findings in curl, software deployed across more than 20 billion instances worldwide.
On August 24, 2026, curl founder Daniel Stenberg wrote that only three CVEs were pending for the next release. After using frontier AI cybersecurity systems to analyze curl, he added:
"[Anthropic] Mythos says it can’t find any more. ... [OpenAI] Codex security shows an empty list."

Daniel Stenberg’s August 24 post: the public, timestamped zero-result that preceded AISLE’s findings.
Daniel had recently documented Mythos's results on curl, one of the world's most heavily audited codebases which is deployed everywhere from smart fridges to spacecraft. We then ran AISLE's autonomous AI system against curl.
The next day, before the review process was complete, Daniel posted: "Mythos: 0
Aisle: 29".

The next day, Daniel posted the first public comparison: Mythos 0, AISLE 29 reports.
Of the 29 AISLE reports, 6 were reviewed within days by curl’s security team, which deemed them serious enough to merit a public CVE designation for curl 8.22.0, which has just been released. They are:
- CVE-2026-80229: OpenSSL provider use-after-free
- CVE-2026-80230: OpenSSL pinning bypass
- CVE-2026-80231: native CA store connection reuse
- CVE-2026-80255: secure attribute bypass with tab
- CVE-2026-82208: wolfSSL CA-cache hit overrides callback
- CVE-2026-82209: domain-scoped public-suffix cookie
All six are rated Low severity. This profile is consistent with curl's exceptional engineering maturity: the vulnerabilities that remain tend to hide in narrow configurations and subtle interactions, limiting their practical impact. All six were fixed in curl 8.22.0 and officially credit Stanislav Fort (from AISLE) as the reporter. Three were reported on August 24, two on August 26, and one on August 27, 2026.
Unlike typical evaluations of AI for cybersecurity, this was not a capture-the-flag challenge or a benchmark with known answers that might already appear in model training data. AISLE analyzed current production code, and curl’s maintainers, not us, decided both whether each finding was real and whether it warranted a CVE.
Because Daniel Stenberg published the frontier AI systems’ zero-result before we ran AISLE, the comparison had an unusually clean property in that the baseline was public and timestamped before our result existed. CVEs are imperfect markers, but they provide unusually strong external validation for zero-day discovery, since each is a previously unknown flaw in production code, reproduced and accepted by domain experts, then fixed for deployed users.
By August 28, curl’s pending CVE count had risen from three to ten. Six of those ten came from AISLE, following the publicly reported zero-result from Anthropic's and OpenAI's frontier AI systems.
The pattern may not be limited to curl. Greg Kroah-Hartman, the longtime maintainer of Linux stable releases, responded to Daniel’s post saying: "I'm seeing the same for Linux as well. No idea what Aisle is doing differently, but wow..."

Greg Kroah-Hartman reported seeing the same pattern in the Linux kernel.
This is another in a growing series of head-to-head results supporting our System over Model thesis: specialized AI systems can compete with and outperform systems from frontier AI labs at real-world zero-day discovery.
On curl, the result was six to zero.
See What AISLE Finds in Your Code
The same discovery engine that powered our findings in curl and Linux is available as a one-time AI code audit: AISLE Snapshot. See what our AI finds in your code, wherever it lives: air-gapped, on-prem, or in the cloud. Get your Snapshot.