curl founder Daniel Stenberg says Mythos identified five vulnerabilities in curl, but a manual review found three were false positives and one was “just a bug”
daniel.haxx.se Daniel Stenberg
Related Coverage
- Anthropic's bug-hunting Mythos was greatest marketing stunt ever, says cURL creator The Register · Brandon Vigliarolo
- Google Says It Found Evidence of Hackers Using AI to Discover a Zero-Day Vulnerability Gizmodo · Bruce Gil
- The developer of curl tried using Anthropic's Mythos to find security vulnerabilities. While it flagged 5 issues, 3 were false positives and 1 just a regular bug. So it only found 1 real security issue. — That said curl already uses multiple AI vulnerability scanners and fuzzers. … @carnage4life@mas.to · Dare Obasanjo
- Mythos Finds a Curl Vulnerability Hacker News
- Mythos finds a curl vulnerability Lobsters
- Anthropic's Bug-Hunting Mythos Was Greatest Marketing Stunt Ever, Says cURL Creator Slashdot · BeauHD
- Anthropic's Mythos cracked software open like an egg. It's just the beginning The Logic · David Reevely
- Claude Mythos Finds Only One Curl Vulnerability; Experts Divided On What It Really Means SecurityWeek · Eduard Kovacs
Discussion
-
@morqon
Morgan
on x
mythos scans curl, finds one “severity low” vulnerability, one bug, and three false positives already described in the docs [image]
-
@zackkorman
Zack Korman
on x
Mythos found a single vulnerability in cURL (along with three false positives, and one issue they classified as a bug). The founder/lead dev wasn't super impressed. [image]
-
@lukolejnik
Lukasz Olejnik
on x
“I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos”. But: read-up. https://daniel.haxx.se/... [image]
-
@martenmickos
@martenmickos
on x
Mythos found one (1) vulnerability in curl - an open-source software product with an installed base of 20 billion instances. https://daniel.haxx.se/...
-
@stdlib
@stdlib
on bluesky
lol someone on lobsters actually suggested Mythos did not find a bug here and Anthropic might secretly be buying black market exploits and passing them off as if they were from Mythos. we are approaching unimaginable, unhealthy levels of cope daniel.haxx.se/blog/2026/05...
-
r/BetterOffline
r
on reddit
Mythos finds a vulnerability in curl, a single low severity one, and curl's creator is not impressed, calls it “a succesful marketing stunt”.
-
r/ClaudeAI
r
on reddit
Curl maintainer utilized Anthropic's Mythos scan: 1 confirmed vulnerability and ~20 bugs
-
r/theprimeagen
r
on reddit
Mythos finds a curl vulnerability
-
r/claude
r
on reddit
Anthropic's bug-hunting Mythos was greatest marketing stunt ever, says cURL creator
-
r/netsec
r
on reddit
Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results