AISLE finds 6 curl CVEs days after OpenAI and Anthropic security systems reported zero
stanislavfort · x · 2026-09-02
What happened
- curl, deployed in over 20 billion instances, was analyzed by frontier AI security systems; on Aug 24, 2026, curl founder Daniel Stenberg reported Anthropic Mythos found nothing and OpenAI Codex Security returned an empty list.
- AISLE then ran its autonomous AI system on curl; Stenberg publicly posted the comparison the next day: Mythos 0, AISLE 29 reports.
- curl's security team reviewed and validated 6 of them as CVEs, shipped in curl 8.22.0.
The six CVEs
- CVE-2026-80229: OpenSSL provider use-after-free
- CVE-2026-80230: OpenSSL pinning bypass
- CVE-2026-80231: native CA store connection reuse
- CVE-2026-80255: secure attribute bypass with tab
- CVE-2026-82208: wolfSSL CA-cache hit overrides callback
- CVE-2026-82209: domain-scoped public-suffix cookie
All six are rated Low severity — consistent with curl's exceptional engineering maturity, with remaining bugs hiding in narrow configurations and subtle interactions.
More from Models
- Gemini 3.8 Flash rumored imminent, but users may need convincing — CtrlAltDwayne · 2026-09-02
- WSJ: Google Set to Ship Coding-First Gemini 3.8 Flash, Codenamed Skimaki — ChuckDBrooks · 2026-09-02
- Gemini 3.8 Flash Expected to Drop Tonight, Echoing WSJ Report — xiaohu · 2026-09-02
- Day-one review: Fable 5.1 a big step up for serious codebases, coordination shines — xeophon · 2026-09-02
- OpenAI's impossible cybersec task seeded the AI 'rebellion' story — show the prompt — BecauseCulture · 2026-09-02
- Most open-source AI text detectors can't hold a 0.5% false-positive rate — grumpyp2 · 2026-09-02