AISLE Finds Six New cURL CVEs After Anthropic Mythos And OpenAI Codex Returned Zero

AISLE's autonomous AI system produced 29 vulnerability reports against cURL — six accepted as CVEs in curl 8.22.0 — days after Anthropic Mythos and OpenAI Codex Security publicly returned zero.

AISLE Finds Six New cURL CVEs After Anthropic Mythos And OpenAI Codex Returned Zero

An AI-native cybersecurity startup called AISLE said on September 2 that its autonomous vulnerability-finding system produced six new CVEs in cURL, one of the most audited codebases in the world — after Anthropic's Mythos and OpenAI's Codex Security both returned zero findings on the same code just days earlier.

A public zero-result, then 29 reports

The head-to-head lands because of an unusually clean timeline. On August 24, cURL founder Daniel Stenberg posted publicly that only three CVEs were pending for the next release and that both Anthropic Mythos and OpenAI Codex Security had come back empty. AISLE ran its system the next day; Stenberg posted "Mythos: 0 / Aisle: 29" almost immediately.

Six of those 29 became real CVEs

Of the 29 reports, cURL's security team accepted six as CVEs in the freshly released curl 8.22.0: CVE-2026-80229 (OpenSSL provider use-after-free), CVE-2026-80230 (OpenSSL pinning bypass), CVE-2026-80231 (native CA store connection reuse), CVE-2026-80255 (secure attribute bypass with tab), CVE-2026-82208 (wolfSSL CA-cache hit overrides callback) and CVE-2026-82209 (domain-scoped public-suffix cookie). All six are rated Low severity — consistent, AISLE argues, with cURL's exceptional engineering maturity: the bugs that remain live in narrow configurations and subtle interactions. Stanislav Fort of AISLE is credited as the reporter on each.

AISLE autonomous AI vulnerability discovery vs frontier LLMs on cURL

Not a benchmark, live code

What makes the result unusual: this was not a capture-the-flag exercise or an evaluation with known answers that might already be in a model's training data. AISLE ran against current production code, and cURL's maintainers — not the vendor — decided which findings merited a CVE. Longtime Linux stable-tree maintainer Greg Kroah-Hartman said publicly he is "seeing the same for Linux as well" from AISLE.

Specialists versus frontier labs

AISLE frames the result as evidence for its "System over Model" thesis — that a specialised AI system built around vulnerability discovery can, at least on real-world zero-day hunts, out-produce raw frontier LLMs. The claim slots into a wider debate over whether autonomous AI red teams should live inside OpenAI or Anthropic — as with Google's Gemini 3.8 Flash Cyber variant or CrowdStrike's SafeMind — or be built by security-native specialists with dedicated program-analysis stacks. On cURL this week, the specialist won 6-0.

Reporting based on AISLE's disclosure, cURL 8.22.0 release notes and posts by Daniel Stenberg and Greg Kroah-Hartman.

Category: Cyber Security

Tags: Cybersecurity OpenAI Anthropic CVE AI Red Teaming Enterprise Software

Related Articles