Technology
AISLE identifies six low-severity curl vulnerabilities after other AI systems found none
Curl maintainers issued six new CVEs for version 8.22.0 following an automated audit by cybersecurity startup AISLE.
The short version
- Autonomous AI security tool AISLE submitted 29 vulnerability reports for the curl codebase, resulting in six verified low-severity CVEs fixed in version 8.22.0.
- The findings came shortly after curl founder Daniel Stenberg reported that models from OpenAI and Anthropic yielded zero new vulnerabilities during tests.
- All six issues were classified as low severity by curl maintainers, reflecting narrow configuration flaws rather than broad exploits.
- Open-source maintainers, including Linux kernel developer Greg Kroah-Hartman, are evaluating the broader efficacy of specialized security AI tools across major codebases.
Key facts
- Curl maintainers designated six new public CVEs in version 8.22.0 based on reports generated by AISLE: CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, and CVE-2026-82209.[Hacker News]
- All six vulnerabilities discovered by AISLE were classified as low severity and resolved in curl release 8.22.0.[Hacker News]
- Curl founder Daniel Stenberg previously noted that frontier systems Anthropic Mythos and OpenAI Codex Security found zero vulnerabilities when tested against the curl codebase.[Hacker News]
- AISLE originally submitted 29 automated vulnerability reports to curl maintainers before the security team validated the six assigned CVEs.[Hacker News]
- Linux kernel maintainer Greg Kroah-Hartman stated publicly that he is observing similar automated vulnerability discovery performance from AISLE on Linux.[Hacker News]
What remains uncertain
- The disposition and validity of the remaining 23 vulnerability reports submitted by AISLE that did not receive CVE designations remain unstated.[Hacker News]