# Anthropic OSS Scanner: Free AI-Driven Vulnerability Scanning for Open-Source Projects (29,000+ Candidate Vulnerabilities Found)

> Anthropic launched OSS Scanner on 2026-10-08, a free, opt-in Claude-based (including Claude Mythos) vulnerability-finding service for critical open-source projects. Over six months it surfaced 29,000+ candidate vulnerabilities, about 6,000 manually reviewed, with about 5,000 unverified reports sent directly to maintainers; defenders should expect higher open-source patch volume.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3165
- **ID:** TL-2026-3165
- **Severity:** INFO
- **Category:** THREAT_INTEL
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-5446

## Description

Anthropic announced OSS Scanner on 2026-10-08 as an opt-in vulnerability-finding service for open-source projects, reported by Security Affairs on 2026-10-09. The service applies Claude's strongest models, including Claude Mythos, with a variety of harnesses and additional token-intensive experimental harnesses, to find memory-safety, cryptographic and logic bugs in project source code. The reporting pipeline consists of vulnerability scanning, agent double-checking of each bug, candidate patch generation and root-cause analysis; maintainers then receive bundled email reports that include a reproducer, an explanation of the vulnerability, bisection analysis and a candidate patch.

Reported results: over roughly six months the scanner produced 29,000+ candidate vulnerabilities. About 6,000 were manually reviewed and triaged by Anthropic, and about 5,000 unverified, fully model-generated reports were shared directly with requesting maintainers without human review. Of 97 critical/high-severity findings validated by expert penetration testers, 85 (88%) met coordinated vulnerability disclosure (CVD) standards, 11 were duplicates of known issues and 1 was a false positive. Anthropic cites the CyberGym benchmark, where detection reportedly rose from under 20% to over 85% in about a year.

Maintainer feedback cited in the sources: Daniel Stenberg (curl) reported multiple issues including one of the worst curl vulnerabilities reported in years (no detail published); Todd Ouska (wolfSSL) said that of 74 reports all but two were valid and five became CVEs; Anton Arapov (OpenSSL) said raw model output was as good as and sometimes better than what maintainers get from people; PostgreSQL maintainers said several reports came with fixes usable nearly as-is. Earlier Anthropic-attributed wolfSSL findings include CVE-2026-5194 (missing hash, digest-size and OID checks in certificate signature verification, rated critical in reporting) and CVE-2026-5446 (ARIA-GCM nonce reuse in TLS 1.2 record encryption, rated high); the sources do not state which five CVEs OSS Scanner produced, so these are context rather than confirmed OSS Scanner output.

Program mechanics: core maintainers apply by submitting a GitHub pull request adding projects/<project>/project.yaml (repository link, contact email, Dockerfile; optional threat model, GPG key, extra CCs) to the anthropics/oss-scanner repository. Eligibility follows OSS-Fuzz-like criteria: critical impact on infrastructure and user security, exposure to remote attack (especially libraries parsing untrusted input), number of users and dependents, and a demonstrated ability to handle verified high/critical reports. Anthropic states it will not apply a 90-day disclosure period to the unvalidated findings; validated reports follow the standard 90-day CVD process. Scanning runs in hardened sandboxes with internet access disabled and reports are held in an access-restricted Anthropic cloud project.

Defender implications: no active exploitation, PoC, actor, CVSS or IOCs are stated for this item, and no CVE is attributed to it by name. It is tracked as an informational trend: AI-driven large-scale vulnerability discovery will likely increase the volume and pace of open-source patches, shrinking the window between discovery and fix, and the same capability class could be used offensively by others (Anthropic has said it does not plan general release of Claude Mythos Preview because of its cyber capabilities). Recommended actions are to prepare patch-management capacity for higher advisory volume in curl, OpenSSL, wolfSSL and similar libraries and to track upstream advisories.

## MITRE ATT&CK

- T1595.002 Vulnerability Scanning
- T1592 Gather Victim Host Information
- T1588.006 Vulnerabilities
- T1587.004 Exploits
- T1190 Exploit Public-Facing Application
- T1195.001 Compromise Software Dependencies and Development Tools
- T1553 Subvert Trust Controls

## Sources

- [Claude Helps Secure Open Source as Anthropic Offers Free Vulnerability Scanning (Security Affairs)](https://securityaffairs.com/200685/ai/claude-helps-secure-open-source-as-anthropic-offers-free-vulnerability-scanning.html)
- [Anthropic: Launching an opt-in vulnerability-finding service for open source](https://www.anthropic.com/research/launching-opt-in-vuln-finding-service-for-open-source)
- [Anthropic Red Team: OSS Scanner](https://red.anthropic.com/oss-scanner)
- [anthropics/oss-scanner GitHub repository (enrollment via PR)](https://github.com/anthropics/oss-scanner)
- [Anthropic CVD findings: wolfSSL CVE-2026-5446 (ARIA-GCM nonce reuse)](https://red.anthropic.com/2026/cvd/findings/ANT-2026-SB4PHA43)
- [Anthropic's Claude found real flaws in encryption used by billions of devices (Startup Fortune)](https://startupfortune.com/anthropics-claude-found-real-flaws-in-encryption-used-by-billions-of-devices/)
- [CVE-2026-5194: wolfSSL certificate signature verification flaw (IT-Connect)](https://www.it-connect.fr/cve-2026-5194-quand-un-bug-dans-wolfssl-valide-des-certificats-falsifies/)
- [Anthropic launches Project Glasswing (Infosecurity Magazine)](https://infosecurity-magazine.com/news/anthropic-launch-project-glasswing)
- [Anthropic says its most powerful AI cyber model is too dangerous to release (VentureBeat)](https://venturebeat.com/data/anthropic-says-its-most-powerful-ai-cyber-model-is-too-dangerous-to-release)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3165
