Autonomous AI agents uncover 6 CVEs in curl, including a bug from 2001

By Carlos Montiel | Enterprise AI Specialist
Leer en español →
Published: 2026-09-03 | By: Carlos Montiel | Reading time: ~5 min

Cybersecurity startup AISLE reported discovering 6 new vulnerabilities (CVEs) in curl using autonomous AI agents for code auditing, including CVE-2026-8932, a memory-handling bug dating back to curl 7.7 in March 2001 — the oldest reported issue in the project's history.

How AISLE's agents work

AISLE runs a system that covers the entire vulnerability lifecycle: detection, verification, and generation of patches ready for human review, autonomously and without disrupting maintainers' workflow. According to the company, it has responsibly discovered and disclosed more than 225 vulnerabilities across 30+ widely used open source projects, including OpenSSL, curl, FreeBSD, and OpenEMR. In UC Berkeley's independent vulnerability-detection benchmark, AISLE ranked #1 in three categories: CVE volume, CWE breadth (weakness types), and MITRE Top 25 coverage.

The specific bugs in curl

The 6 CVEs identified in curl range from classic memory-lifetime issues to logic bugs in how libcurl decides whether a connection, credential, or host identity is still valid. The curl project, which cancelled its paid bug bounty program this year, has been proactively using AISLE to detect and fix vulnerabilities since February 2026, according to the company's own reports and specialized security press coverage.

Risk context: curl is one of the most embedded libraries on the planet — present in virtually every piece of software that makes HTTP requests, from mobile apps to connected appliances. A 25-year-old undetected bug in such a ubiquitous library underscores that the surface of legacy vulnerabilities in critical software remains enormous, even in mature, well-audited projects.
Impact for companies using or buying AI: this case is concrete evidence that autonomous code-auditing agents already outpace traditional manual review in volume and depth on critical open source projects. If your company depends on third-party libraries (and nearly all do, directly or indirectly, on curl), it's worth asking your vendors whether they use agentic auditing tools as part of their security pipeline — and seriously considering similar tools to audit your own internal code before someone else does.
Carlos Montiel
Enterprise AI Solutions Architect
LLMs, Agents & Orchestration Specialist
guatemalia.com/#contacto · info@guatemalia.com

Need to implement AI in your company?

Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.

Contact Carlos Montiel

info@guatemalia.com