Curl seems to becoming one of the favourite things to demo AI finding vulns.
Curl is going to end up incredibly secure.
Thank goodness because curl is a load bearing structure to the backend of the internet.
Anyone care to guesstimate how much effort there would be in creating an actually-secure curl and openssl? Using something like Common Lisp or Lean, instead of C.
Curl has a well earned reputation for high quality code. If you find something there it means you are good. There is a lot of software where finding a vulnerability mostly means you bothered to look and are not completely stupid. Nobody is going to be impressed if you find an issue with something that everybody already knows is poorly coded.