ai-securityvulnerability-reportingmaintainer-burnoutcurl

The New Stack - Daniel Stenberg / AI DDoSing Open Source

Highlights the emerging risk of 'AI slop' security reports that burn out maintainers while acknowledging the unique value of AI-powered protocol analysis.

Summary

Daniel Stenberg, creator of cURL, warns that AI is 'DDoSing' open-source maintenance through a flood of bogus, LLM-generated security reports. Since 2025, the accuracy rate of security reports for cURL has plummeted from 1-in-6 to 1-in-30, primarily due to 'AI slop'—long, confident, but completely fabricated vulnerability claims designed to chase bug bounties (up to $10,000 for critical issues). This noise risks creating 'security numbness' among maintainers, potentially causing real flaws to be ignored. However, Stenberg also notes that AI-powered analyzers have uncovered over 100 deep bugs in cURL that no traditional tools or human audits ever found, illustrating a critical divide between AI-generated noise and AI-powered deep analysis.

Gaps Analysis

Evidence

The rate has gone up to now it’s more like one in 20 or one in 30 [reports], that is accurate... turning security bug report triage into 'terror reporting'.

Blind Spot

Risk Guard trusts vulnerability database records but doesn't account for the 'Report Quality' or the likelihood that a CVE was a false-positive generated by AI slop.

Actionable Capability

Risk Guard would be better if it integrated a 'CVE Confidence' score that penalized findings from historically low-accuracy reporters or bot-heavy domains.

← Previous Next →