Daniel Stenberg, the creator of curl, stated on 2026-08-24 that there were only three pending CVEs for the next release. He reported that no vulnerabilities were detected after analyzing curl using Anthropic's Mythos and OpenAI's Codex Security.
AISLE Discovers 6 CVEs in curl After OpenAI and Anthropic AI Failed to Detect Vulnerabilities
This article is a translation. Read the Japanese original
However, AISLE subsequently analyzed curl using its autonomous AI system, which generated 29 reports. Of these, six were verified by the curl security team and judged to be serious.
All of these vulnerabilities have been fixed in the newly released curl 8.22.0. All reported vulnerabilities are rated as Low severity.
Additionally, Greg Kroah-Hartman, a maintainer of the Linux stable branch, stated that similar patterns are observed within the Linux kernel.
Source: Six curl CVEs after OpenAI and Anthropic came back with zero (Hacker News Frontpage, 2026-09-02)