← Latest briefing

Technology

AISLE identifies six low-severity curl vulnerabilities after other AI systems found none

Curl maintainers issued six new CVEs for version 8.22.0 following an automated audit by cybersecurity startup AISLE.

The short version

  • Autonomous AI security tool AISLE submitted 29 vulnerability reports for the curl codebase, resulting in six verified low-severity CVEs fixed in version 8.22.0.
  • The findings came shortly after curl founder Daniel Stenberg reported that models from OpenAI and Anthropic yielded zero new vulnerabilities during tests.
  • All six issues were classified as low severity by curl maintainers, reflecting narrow configuration flaws rather than broad exploits.
  • Open-source maintainers, including Linux kernel developer Greg Kroah-Hartman, are evaluating the broader efficacy of specialized security AI tools across major codebases.

Key facts

  • Curl maintainers designated six new public CVEs in version 8.22.0 based on reports generated by AISLE: CVE-2026-80229, CVE-2026-80230, CVE-2026-80231, CVE-2026-80255, CVE-2026-82208, and CVE-2026-82209.[Hacker News]
  • All six vulnerabilities discovered by AISLE were classified as low severity and resolved in curl release 8.22.0.[Hacker News]
  • Curl founder Daniel Stenberg previously noted that frontier systems Anthropic Mythos and OpenAI Codex Security found zero vulnerabilities when tested against the curl codebase.[Hacker News]
  • AISLE originally submitted 29 automated vulnerability reports to curl maintainers before the security team validated the six assigned CVEs.[Hacker News]
  • Linux kernel maintainer Greg Kroah-Hartman stated publicly that he is observing similar automated vulnerability discovery performance from AISLE on Linux.[Hacker News]

What remains uncertain

  • The disposition and validity of the remaining 23 vulnerability reports submitted by AISLE that did not receive CVE designations remain unstated.[Hacker News]

Sources