TRENDING
Two orange safety relief valves on grey pressure vessels in an industrial plant
October 9, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
October 9, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
A lugworm lying on wet sand and mud at low tide
October 9, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
An 1840 Mulready postal envelope with a red Leicester postmark dated 4 May 1840 and a handwritten address
How to Audit SPF, DKIM, and DMARC in Python to Stop Spoofed Email From Using Your Domain
October 9, 2026
Wooden two-dial chess clock with brass-rimmed white faces showing different times
A CNCF Post on NIS2 and DORA Turns Compliance Into a Backlog and Leaves the Classification Call Unowned
October 9, 2026
A hand holding an egg against a bright light in a dark room, with the light shining through the shell to show what is inside
Anthropic Launches OSS Scanner to Email Open-Source Maintainers AI Bug Reports No Human Has Reviewed
October 9, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 233 Posts
News 235 Posts
Learning Hub 205 Posts
Home/News/Anthropic Launches OSS Scanner to Email Open-Source Maintainers AI Bug Reports No Human Has Reviewed
News

Anthropic Launches OSS Scanner to Email Open-Source Maintainers AI Bug Reports No Human Has Reviewed

Anthropic’s opt-in OSS Scanner emails model-generated vulnerability reports to open-source maintainers with no human review and no 90-day disclosure clock, and wolfSSL’s CVE table already lists five...

October 9, 2026 9 Min Read
6

Anthropic on Thursday launched OSS Scanner, a free, opt-in service that scans open-source projects with its strongest models and emails the findings to maintainers. The company says the output “will be fully model-generated, without human review or triage.” The same announcement introduced a Critical Infrastructure Defense Program for the vendors and consultancies that secure power, water and transport systems.

Table Of Content

  • What OSS Scanner Does and Who Can Join
  • Anthropic’s Accuracy Numbers, and Who Checked Them
  • What Public Records Show So Far
  • wolfSSL
  • pyca/cryptography
  • curl
  • The Terms Put the Review on the Maintainer
  • Day One on GitHub: Signups, No Merges
  • The Second Program: Critical Infrastructure Defense
  • What Maintainers Should Check Before Enrolling
  • What to Watch

The design follows from a number Anthropic published alongside it. Over six months its models produced more than 29,000 candidate vulnerabilities, and its staff have manually triaged about 6,000 of them. Anthropic says it remains “bottlenecked on our human capacity to validate these findings,” and that maintainers who asked for everything have already received nearly 5,000 unvalidated reports. OSS Scanner makes that arrangement a standing service and skips the check for projects that ask for it, and the service terms leave the checking to the maintainer.

I checked what I could against public records. wolfSSL’s vulnerability table marks exactly five CVEs “Found via the Anthropic OSS program,” and three commits in the pyca/cryptography repository carry the scanner’s credit line. curl’s published advisory list does not yet credit Anthropic for anything. SecurityWeek and The Verge both covered the launch.

What OSS Scanner Does and Who Can Join

Maintainers enroll a project by opening a pull request against the anthropics/oss-scanner repository. The request adds a project.yaml file with the repository address and a contact email, a pointer to a Dockerfile (kept in the project’s own repository or next to the config) that installs every dependency and builds the project, and optionally a threat_model.md that tells the scanner what to treat as hostile input and how to rate severity. According to the README, the scanner builds the project in an isolated virtual machine, then analyzes it “with no Internet access” and emails what it finds, “each with a reproducer and a proposed patch where available.”

Anthropic says eligibility follows “a similar set of criteria” to OSS-Fuzz, Google’s fuzzing program for open-source software. Projects need a “critical impact on infrastructure and user security,” decided case by case, and Anthropic says it will manually confirm that whoever enrolls a project is a core maintainer. The service FAQ also says who the service is meant for: it is “built for projects that are already able to keep up with verified high/critical vulnerability reports.” Everyone else keeps getting human-checked disclosures through Anthropic’s existing coordinated vulnerability disclosure process. Anthropic says it covers the full cost, and that its Defender Advantage Fund “keeps OSS Scanner free.”

Anthropic’s Accuracy Numbers, and Who Checked Them

The evidence for the unreviewed approach comes from an early version of the scanner. Anthropic asked “the expert penetration testers who review our CVD findings” to check 97 critical and high-severity findings across 48 projects. Of those, 85 (88%) met the bar for its disclosure process. Of the other 12, 11 were real but duplicated known issues or other findings from the same scan, and one was invalid. That works out to 96 of 97 findings being real, though the reviewers were Anthropic’s own and the sample covered only the scanner’s top two severity labels.

For the live service Anthropic sets a looser bar. Its Cyber Mission post says, “We expect a true-positive rate above 90%.” The launch post adds that maintainers have told it “severity ratings can be inflated or the scanner misunderstood the project’s threat model.”

The maintainers Anthropic quotes are positive. wolfSSL’s Todd Ouska says that “of the 74 reports we received, all but two were valid, and five became CVEs.” Anton Arapov of OpenSSL Corporation says the reports, raw model output included, “were as good and sometimes better than what we get from people.” curl’s Daniel Stenberg says OSS Scanner found “one of the worst curl vulnerabilities reported in the last few years.” These are testimonials Anthropic chose to publish.

What Public Records Show So Far

Claim Who made it What public records show
Five wolfSSL reports became CVEs wolfSSL’s Todd Ouska, quoted by Anthropic wolfSSL’s table lists five CVEs marked “Found via the Anthropic OSS program,” all fixed in 5.9.4: one High, one Medium, three Low
Fixes credit the scanner by report ID Anthropic’s FAQ asks maintainers to add one Three pyca/cryptography commits on September 18 and 19 (UTC) carry six ANT-2026 report IDs
“One of the worst curl vulnerabilities reported in the last few years” curl’s Daniel Stenberg, quoted by Anthropic None of the 215 entries in curl’s vulnerability list credits Anthropic or OSS Scanner (checked October 9)
85 of 97 critical and high findings met the disclosure bar Anthropic’s own penetration testers Not checkable from outside

wolfSSL

wolfSSL’s 5.9.4 release, published September 27, carries the five. The vulnerability table rates CVE-2026-93302 High: a trusted-peer check that ignores the public key, so forged CA clones pass verification. It rates CVE-2026-93304 Medium: a (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. The other three, CVE-2026-94417, CVE-2026-94418 and CVE-2026-94419, are Low. The table lists the time to fix as one day for the first two and four days for the other three. The label says “Anthropic OSS program” rather than OSS Scanner, but the count matches Ouska’s “five became CVEs.” Older rows in the same table thank Anthropic researchers by name for separate reports, so the label matters: only these five carry the program wording.

pyca/cryptography

The first commit releases the Python global interpreter lock while parsing PKCS#12 bundles so other threads are not stalled. The second makes an oversized SCT list raise ValueError instead of being silently encoded with a wrapped length. The third rejects overlapping input and output buffers in the library’s *_into methods, whose old behavior the commit message describes as “silently producing incorrect results (in the AEAD case, with a valid tag).” Each says “Discovered by Anthropic’s OSS Scanner, as vulnerability” followed by an ID of the form ANT-2026-XXXXXXXX: ANT-2026-S35HH95Z for the first, ANT-2026-H08T92Y2 for the second, and four IDs for the third. They are real fixes, but none of the three commit messages mentions a CVE, and the first is a thread stall rather than memory corruption.

curl

curl’s machine-readable vulnerability list had 215 entries when I checked. The only one that mentions Mythos is CVE-2026-8286, rated Low and published June 24, which credits “Andrew Nesbitt (powered by Mythos)” as the finder. Nothing credits Anthropic or OSS Scanner, so Stenberg’s “one of the worst” finding cannot be matched to a published advisory yet. It may still be unpublished.

The same project is the best-known case of the opposite experience. On January 26 Stenberg announced the end of curl’s bug bounty, writing that the share of submissions confirmed as vulnerabilities had gone from “somewhere north of 15%” in earlier years to “below 5%” starting in 2025. The pipelines differ. curl’s bounty was an open inbox with money attached, while OSS Scanner is opt-in, approved by hand, run by one vendor, and ships a reproducer and a candidate patch with each report.

The Terms Put the Review on the Maintainer

The disclosure policy is the biggest change from standard practice. The FAQ says: “We will not place any form of 90-day coordinated disclosure period on these unvalidated findings.” The README adds that Anthropic “will not make them public.” Anthropic’s stated reason is fairness: “we do not feel comfortable forcing maintainers to carefully read each finding if we have not yet done the same.” If Anthropic later validates a report by hand, it may disclose the bug under its normal policy starting 90 days after it tells the maintainer, and it says it may add a disclosure period to some high-severity reports in future with notice and an option to opt out.

The agreement maintainers accept when they enroll spells out the rest. Reports are “Anthropic’s confidential material” and provided “as is.” The participant “is responsible for reviewing each Report, and any patch proposed in it, before making changes to the Project in reliance on a Report or sharing that Report.” Reports may be shared only with “authorized maintainers of the Project,” and must be kept confidential until the bug is fixed or publicly disclosed. Anthropic’s total liability is capped at $1,000, and it may “modify, suspend, or end the Service, or any enrollment, at any time and for any reason.”

Taken together, the review burden that Anthropic calls its own bottleneck moves to the maintainer on the receiving end, and the 90-day clock does not start until Anthropic’s people have confirmed a report. Anthropic’s launch post says “exploits can now be developed in minutes,” which is the case for speed. The policy drops the public deadline that normally puts a date on a fix. On October 3 we covered a Rejetto HFS flaw found with Anthropic Mythos that attackers were exploiting 11 weeks after its patch, which is the gap between finding and fixing that Anthropic says it wants to shrink.

The launch also lands in a week when the other side of the same problem made news. On October 5 we reported that Google had stopped accepting product vulnerability reports for its open-source bounty, citing automated submissions. The Verge notes that some open-source projects are “struggling to keep up with the sudden onslaught of AI-generated bug reports.” Anthropic’s design sends the volume only to maintainers who ask for it, and it gates enrollment by hand.

Day One on GitHub: Signups, No Merges

I queried the enrollment repository’s public API at 10:19 UTC on October 9. The repository was created at 17:25 UTC on October 8. By then it had 107 enrollment pull requests from 78 accounts, 92 open and 15 closed. None had been merged, and the repository had no projects folder on its main branch yet. Anthropic’s README says it reviews and merges enrollment pull requests, and its FAQ says it will validate maintainers by hand before enrolling a project, so a queue is expected. From outside I cannot tell how fast it moves.

Projects are preparing anyway. GitHub’s commit search for “Anthropic’s OSS Scanner” returns commits in go-jose, vyper, mise and OneUptime that add build files or threat models for the service. OneUptime’s was merged from a branch named claude/oss-scanner-enrollment. Repository automation has also flagged one early enrollment request because its opener was not an author of any commit in it. The commit authors were Claude accounts.

The Second Program: Critical Infrastructure Defense

The Critical Infrastructure Defense Program has 11 founding partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation. Anthropic says the program “brings frontier models, on-site engineers, and threat research to the defenders that protect operational technology.” It reaches plant operators through those providers rather than directly: Anthropic notes that “operators of every size rely on a small set of trusted providers.”

The post is short on measurable detail. It gives no dollar figure, names no operator, and reports no result beyond “Several partners are currently working with Claude to fix vulnerabilities and help customers do the same.” Anthropic is starting with “a small cohort” and says it will bring the program to more partners and sectors over the coming months. It also names the constraint that makes operational technology different: equipment often cannot be taken offline, and a fix may have to wait until it can be applied safely, “in some rare cases, this might take decades.”

What Maintainers Should Check Before Enrolling

  • The contact addresses in project.yaml are public, according to the README, so use a security alias. A PGP key cannot be combined with extra CC addresses.
  • The scanner works from a Dockerfile you supply. Setup has network access and the audit does not, and the README suggests running tools/check first. That tool installs Claude Code into the image it builds, so run it only on projects you trust.
  • A threat_model.md is “optional but strongly recommended.” It is where you say how severity should be rated, which matters given Anthropic’s own note about inflated ratings.
  • Decide who triages before you enroll. The terms make that your job, and disabled: true pauses reports without withdrawing the project.
  • Anthropic asks for the report ID in the commit message when you fix something, so it can track impact.

What to Watch

The first merged enrollments will show how large the early cohort is. The commit histories of enrolled projects will then show the real yield, because the credit line makes scanner fixes searchable. The wolfSSL ratio of one High among five CVEs is a small sample, and the 90% true-positive expectation has to hold up at scale. The no-deadline policy is also provisional: Anthropic says it may change it, with notice.

Tags:

AI SecurityAnthropicCritical InfrastructureOpen Source MaintainersOpen Source SecurityVulnerability Disclosure

Share

Two orange safety relief valves on grey pressure vessels in an industrial plant
Previous Post

How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down

Wooden two-dial chess clock with brass-rimmed white faces showing different times
Next Post

A CNCF Post on NIS2 and DORA Turns Compliance Into a Backlog and Leaves the Classification Call Unowned

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
09 Oct
How to Audit SPF, DKIM, and DMARC in Python to Stop Spoofed Email From Using Your Domain
09 Oct
A CNCF Post on NIS2 and DORA Turns Compliance Into a Backlog and Leaves the Classification Call Unowned
Trending
October 9, 2026
How to Audit SPF, DKIM, and DMARC in Python to Stop Spoofed Email From Using Your Domain
October 9, 2026
A CNCF Post on NIS2 and DORA Turns Compliance Into a Backlog and Leaves the Classification Call Unowned
October 9, 2026
Anthropic Launches OSS Scanner to Email Open-Source Maintainers AI Bug Reports No Human Has Reviewed
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A customer-support representative wearing a headset against a dark studio background.
Articles

The Meta AI Support Hack Was a Plain Old Authorization Failure

June 7, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026