Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

AI Changes How curl Handles Security Reports

AI tools are changing how the curl project receives and handles security reports, according to curl creator Daniel Stenberg. curl includes a command-line tool and the libcurl library, which transfer data between systems and are used in operating systems, apps, servers and other products.

Stenberg’s figures show that the average interval between reports fell from about 116 hours between 2020 and 2024 to about 14 hours during 2026. More than half of the reports now concern real code defects, and about one in six leads to a confirmed security vulnerability. The vulnerabilities discovered have existed in the code for about eight years on average.

Earlier AI-assisted reports often appeared convincing but could not be reproduced. The workload has now shifted from finding suspicious code to understanding the context, assessing exploitability, identifying affected versions and preparing fixes. In July, the project temporarily closed new report submissions for one month so its maintainers could handle other work and take time off. When submissions reopened, about 45–50 reports arrived in a short period.

Stenberg began the project’s predecessor in the 1990s and named it curl in 1998. As he approaches 30 years with the project, he says more than 1,500 people have contributed code. He also sees potential for AI to help review AI-generated fixes, while keeping final decisions with people.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.