Anthropic’s Mythos vulnerability-hunting model identified five purported security issues in the curl codebase, but curl founder Daniel Stenberg and the project’s security team validated only one as a real vulnerability. Stenberg said three findings were false positives already addressed by API documentation, while another was a non-security bug; the sole confirmed issue is described as low severity and is expected to be fixed in curl 8.21.0, with disclosure planned alongside that release. He said the model was tested through Anthropic’s Project Glasswing rather than by direct access to the repository.
Stenberg said the results did not support claims that Mythos is uniquely effective at finding software flaws, calling the surrounding promotion more marketing than breakthrough. He added that AI-assisted code analysis is still useful and has improved substantially over traditional static analysis, but argued Mythos showed no clear advantage over other modern AI tools already used on curl’s heavily audited codebase. Broader discussion in the security community has also pointed to orchestration frameworks and workflow design—not just frontier models—as effective ways to uncover vulnerabilities, reinforcing skepticism that a single high-end model alone represents a major leap in bug hunting.

Track how attackers are adapting to this technology.
6 events from the most recent confirmed update back to the earliest known activity.
curl publicly disclosed CVE-2026-8286, a low-severity flaw in its connection cache that could reuse a connection with the wrong security state when a request required a STARTTLS-upgraded connection. The advisory credited Andrew Nesbitt, powered by Mythos, as the finder and confirmed the issue previously discussed by Daniel Stenberg.
Stenberg said the single confirmed Mythos-found curl issue is planned for disclosure and remediation in curl 8.21.0. The references anchor the planned release timing only as late June, not a specific day.
Daniel Stenberg published his assessment that Anthropic's Mythos reported five confirmed security issues in curl, but curl maintainers validated only one as a genuine low-severity vulnerability. He said the other findings were false positives already covered by documentation or a non-security bug.
A Risky Business Features podcast episode discussed research into finding zero-days with older AI models and highlighted Niels Provos' Iron Curtain orchestration framework. The episode framed workflow design and orchestration as an alternative to relying on a single frontier model prompt.
Niels Provos said his interest in AI-assisted bug hunting was sparked after a widely discussed Mythos zero-day vulnerability was found in OpenBSD code he had written 27 years earlier. The provided references do not give a specific date for when that vulnerability was found.
The curl advisory states that Andrew Nesbitt, powered by Mythos, reported the STARTTLS connection-reuse vulnerability later assigned CVE-2026-8286 to the project. The report was submitted before public disclosure and preceded the eventual fix in curl 8.21.0.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
7 references tracked. Mallory keeps watching after this page renders.
curl.se
Open sourcebugflation.com
Open sourcesecurityaffairs.com
Open sourcelwn.net
Open sourcetheregister.com
Open sourcedaniel.haxx.se
Open sourcerisky.biz
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.