Anthropic and OpenAI missed 6 curl vulnerabilities found by Aisle, whose AI-native scanner surfaced six new CVEs in curl 8.22.0 after Mythos and Codex Security reported zero findings.
Anthropic and OpenAI missed 6 curl vulnerabilities found by Aisle
Anthropic and OpenAI missed 6 curl vulnerabilities found by Aisle, according to a new report from the AI‑native cybersecurity startup. Aisle’s autonomous vulnerability‑finding system surfaced six new CVEs in curl 8.22.0, released on September 2, 2026, after both Anthropic’s Mythos and OpenAI’s Codex Security reported zero findings on the same codebase just days earlier.
The result is a striking data point in the debate over AI‑assisted security: even frontier models from major labs can miss real, exploitable bugs in one of the world’s most widely deployed and audited codebases.
What happened: Mythos and Codex found zero
On August 24, 2026, curl founder Daniel Stenberg publicly noted that:
- Only three CVEs were pending for the next curl release.
- Both Anthropic Mythos and OpenAI Codex Security had been run against curl and returned zero additional findings.
The next day, Aisle ran its own system against curl. Stenberg quickly posted a comparison:
“Mythos: 0 / Aisle: 29”
Of Aisle’s 29 reports, curl’s security team reviewed six within days and deemed them serious enough to warrant public CVE designations for curl 8.22.0. 1062
The six CVEs Aisle found
All six vulnerabilities are rated Low severity, but they cover a range of subtle issues in curl’s TLS, cookie, and connection‑handling logic:
All six were:
- Fixed in curl 8.22.0.
- Officially credited to Stanislav Fort of Aisle as the reporter.
Aisle notes that the low severity is consistent with curl’s maturity: the remaining bugs tend to live in narrow configurations and subtle interactions, which are exactly the kind of issues that can slip past both human auditors and general‑purpose AI models.
Why this matters for AI security
The episode highlights several important lessons for organizations relying on AI‑powered security tools:
- Zero findings are not proof of safety.
Even frontier systems from Anthropic and OpenAI can miss real vulnerabilities in a heavily audited codebase. Aisle argues that a “zero result” should be treated as a starting point, not a conclusion. - Specialized AI systems can outperform general models.
Aisle’s platform is purpose‑built for vulnerability discovery and verification, which may explain why it found issues that broader‑purpose models missed. - Defense in depth remains essential.
Security teams should combine AI‑driven analysis with human expertise, continuous monitoring, and layered defenses rather than relying on any single tool. - Independent validation matters.
Claims from AI vendors about security coverage should be tested against real codebases and compared with third‑party results.
Context: Aisle’s track record in curl
This is not Aisle’s first success with curl:
- In June 2026, Aisle reported 6 of 18 CVEs fixed in curl 8.21.0, including the oldest known security issue in the project (CVE‑2026‑8932, dating back to curl 7.7 in March 2001).
- Aisle says it has now found more than 2× the CVEs of the nearest AI security platform in curl and libcurl.
The latest six CVEs reinforce the argument that continuous, AI‑native analysis can uncover issues that periodic audits and general‑purpose models miss.
Summary: Anthropic and OpenAI missed 6 curl vulnerabilities found by Aisle, whose AI‑native scanner surfaced six new CVEs in curl 8.22.0 after Mythos and Codex Security reported zero findings. The episode underscores that even frontier AI security tools have blind spots and that layered, independent validation remains essential