The curl Project Uses AISLE to Find and Fix Vulnerabilities in Code Installed on 20B+ Devices

The curl project needed to secure its nearly-ubiquitous software, which runs on over 20 billion devices, so it chose AISLE. Now curl’s lean team uses AISLE to find and fix vulnerabilities in its codebase, uncovering dozens of issues in one of the world’s most mature, rigorously audited libraries. In the words of curl founder and lead developer Daniel Stenberg, “AISLE is awesome.”
Key Results
Dozens of software vulnerabilities in curl and libcurl found and fixed using AISLE
11 CVEs in curl discovered by AISLE, more than double that of any other AI security company
The curl project can keep its code secure without adding headcount
In late 2025, the curl project, which develops and secures vital open-source libraries installed on over 20 billion devices, closed its paid bug bounty because its lean team had become overwhelmed by a flood of low-quality, AI-generated submissions. But there was a diamond in the rough of AI findings. According to curl founder and lead developer Daniel Stenberg, "a new breed of analyzer" had emerged.
In the months before the curl project retired the paid bounty, 24 curl pull requests were attributed to AISLE and five security issues were assigned CVEs, for a total of 29 valid findings within several months. The curl project then started using AISLE to find and fix vulnerabilities. As Stenberg says, "AISLE is awesome."

Safeguarding Vital Software Infrastructure With AISLE
The curl project develops and secures its nearly ubiquitous command line tool with a full-time team of one and input from the volunteer developers of the open-source community. As machine-generated code analysis strained the incentive systems that make open source possible, the curl project was challenged to accelerate their analysis and remediation workflows.
Stenberg was initially skeptical of the role AI could play in this effort, but he noted that "a new breed of analyzer" had emerged. For instance, AISLE's AI found issues including a QUIC pinned-public-key bypass, a wcurl path traversal, and two additional CVEs in the wolfSSH backend. Based on these results, as well as a solid collaborative relationship with the AISLE team, the curl project started using AISLE to find and propose fixes for vulnerabilities in February 2026.
"AISLE has a powerful analyzer that highlights code areas that need more attention in ways the old generation of code tools have not been able to." — Daniel Stenberg, founder and lead developer of curl
Putting AISLE to the Test
When the curl project used Mythos to analyze its codebase, Stenberg wrote that it found one low-severity CVE. By contrast, 11 curl CVEs have been attributed to AISLE. This result is further confirmation of our thesis that cybersecurity capability is jagged. Rather than being tied to a single frontier model, vulnerability detection is a multi-phase process best solved by a multi-agent system like AISLE’s.
Empowering Security Organizations Using AISLE
The curl project aims to continue using AISLE to both secure its existing code and verify that it does not ship new vulnerabilities in upcoming releases. As Stenberg says, AISLE is "an example of what AI can do for open source security when used for good."


