Cybersecurity startup AISLE reported discovering 6 new vulnerabilities (CVEs) in curl using autonomous AI agents for code auditing, including CVE-2026-8932, a memory-handling bug dating back to curl 7.7 in March 2001 — the oldest reported issue in the project's history.
AISLE runs a system that covers the entire vulnerability lifecycle: detection, verification, and generation of patches ready for human review, autonomously and without disrupting maintainers' workflow. According to the company, it has responsibly discovered and disclosed more than 225 vulnerabilities across 30+ widely used open source projects, including OpenSSL, curl, FreeBSD, and OpenEMR. In UC Berkeley's independent vulnerability-detection benchmark, AISLE ranked #1 in three categories: CVE volume, CWE breadth (weakness types), and MITRE Top 25 coverage.
The 6 CVEs identified in curl range from classic memory-lifetime issues to logic bugs in how libcurl decides whether a connection, credential, or host identity is still valid. The curl project, which cancelled its paid bug bounty program this year, has been proactively using AISLE to detect and fix vulnerabilities since February 2026, according to the company's own reports and specialized security press coverage.
Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.
Contact Carlos Montiel