• Sources: primary, CVE table, reporter, discussion
  • Summary: curl's own CVE table publishes nine advisories dated 2026-09-02, eight rated Low and one Medium, all last affecting 8.21.0 and fixed in 8.22.0. The reporting vendor states its system found six of the nine, and that Anthropic Mythos and OpenAI Codex Security publicly returned zero findings on the same codebase. Every identifier, severity and date in this block was read from curl.se rather than from the vendor post, which is promotional and ends in a sales pitch, and curl's maintainers rather than the reporter decided each finding was real.
  • Why it matters: The fix is a version bump to 8.22.0 rather than a mitigation, and the head-to-head claim is made against a public timestamped zero-result rather than against an internal benchmark.
  • Follow-up: Track whether Anthropic or OpenAI responds to the zero-result comparison, and whether any of the nine advisories is re-rated.

send feedback on this story