All findings

CVE-2026-8925 + 5 more medium

curl 8.21.0 credits AISLE Research on six CVEs

curl's June 2026 security release directly credits Joshua Rogers of AISLE Research on six vulnerabilities spanning authentication state, credentials, memory safety, and protocol handling.

Bug class
Double-free, credential disclosure, authentication-state leakage, and protocol confusion
Affected codebase
curl and libcurl
Credited system
AISLE
Disclosed
June 24, 2026
Attribution
Self-reported attribution
Severity
medium
Source status: curl's machine-readable advisories name Joshua Rogers of Aisle Research as finder on all six CVEs. AISLE's campaign post supplies the autonomous-platform context, so the system attribution is self-reported. Severity follows curl, not AISLE's registry.

Summary

curl 8.21.0 fixed six vulnerabilities reported by Joshua Rogers of AISLE Research. The set includes a SASL double-free, password and authorization-state leaks, and protocol-state mistakes accumulated across different periods of the curl codebase.

The oldest issue in the campaign predates modern AI tooling by many years; the relevant ledger fact is that an AI-native security platform participated in its 2026 discovery and disclosure.

Severity boundary

AISLE’s registry assigns more aggressive scores to some rows. Bugflation uses curl’s own classifications: the cluster is Medium at its highest upstream-rated member, with several Low entries.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.