Anthropic's OSS Scanner: Free AI Tool Finds 72 Valid Bugs in wolfSSL, 5 Become CVEs
Anthropic launched OSS Scanner on October 8, 2026, a free, opt-in AI vulnerability scanner for open-source projects, leveraging its most capable models, including Claude Mythos. This service provides fully model-generated reports to maintainers, and in early tests, wolfSSL confirmed 72 valid findings out of 74, resulting in five new CVEs. For broader context, explore our AI Tools Pricing.
The Genesis of OSS Scanner: Project Glasswing
The development of OSS Scanner emerged from Anthropic's internal initiative, Project Glasswing, which focused on utilizing Claude for large-scale vulnerability discovery. Over a six-month period, Project Glasswing identified more than 29,000 potential vulnerabilities across various software projects. However, the manual triage process proved to be a significant bottleneck, allowing only about 6,000 of these candidates to be reviewed by human experts.
OSS Scanner addresses this challenge by automating the reporting process. It delivers comprehensive reports directly to maintainers who opt into the service. Each report is entirely generated by the AI model and includes a self-contained reproducer, a detailed explanation, a bisection to pinpoint when the bug was introduced (where feasible), and a candidate patch.
Independent Validation and Early Success
To assess the accuracy and utility of the OSS Scanner, Anthropic engaged independent penetration testers to review a subset of its findings. Out of 97 critical and high-severity findings across 48 projects, 85 (88%) met the criteria for Anthropic's coordinated vulnerability disclosure process. Only one finding was identified as a false positive, while 11 were duplicates of already known issues.
The efficacy of the reports has been endorsed by maintainers from prominent open-source projects, including PostgreSQL, OpenSSL, wolfSSL, HotCRP, and curl. Notably, wolfSSL confirmed the validity of 72 out of 74 reported findings, with five of these subsequently being assigned CVEs, underscoring the scanner's practical impact on real-world security.
How OSS Scanner Compares to Existing Tools
Anthropic's OSS Scanner is modeled after Google's OSS-Fuzz, a well-established continuous fuzzing service for open-source software. While both aim to enhance the security of the open-source ecosystem, OSS Scanner distinguishes itself by leveraging advanced large language models (LLMs) for vulnerability detection and report generation. This approach allows for the creation of detailed explanations and even candidate patches, which can streamline the remediation process for maintainers.
The service is provided free of charge for open-source projects, with scans conducted periodically. This contrasts with Anthropic's enterprise offering, Claude Security, which remains a paid product tailored for commercial applications.
Advancements in LLM Vulnerability Detection
Anthropic has reported significant improvements in the capability of LLMs for vulnerability detection. According to their data, LLM performance on the CyberGym benchmark increased from under 20% in early 2025 to over 85% in 2026. This substantial leap in accuracy highlights the rapid progress in applying AI to complex security challenges and underpins the effectiveness of tools like OSS Scanner.
Key Takeaways for Open-Source Maintainers
- Anthropic's OSS Scanner offers a free, AI-powered solution for identifying security vulnerabilities in open-source projects.
- The service provides detailed, model-generated reports, including reproducers, explanations, and potential patches.
- Early results show high accuracy, with independent validation and positive feedback from major projects like wolfSSL.
- OSS Scanner is inspired by Google's OSS-Fuzz but utilizes advanced LLMs for enhanced detection and reporting capabilities.
- Maintainers can opt-in to receive periodic scans and contribute to the overall security of their projects.
Conclusion
The launch of Anthropic's OSS Scanner marks a notable advancement in the application of AI to open-source security. By offering a free, highly effective tool that leverages cutting-edge LLMs, Anthropic aims to significantly reduce the burden of vulnerability discovery and remediation for open-source maintainers. The positive early results, particularly from projects like wolfSSL, suggest that AI-driven security scanning is becoming an increasingly vital component of maintaining robust software ecosystems. Open-source project maintainers are encouraged to explore this code assistance tool to enhance their security posture.
Sources
Recommended AI tools
n8n
Productivity & Collaboration
Open-source workflow automation with native AI
DeepL
Writing & Translation
The world’s most accurate AI translator
Google Cloud Vertex AI
Data Analytics
Gemini, Vertex AI, and AI infrastructure—everything you need to build and scale enterprise AI on Google Cloud.
CustomGPT.ai
Conversational AI
Create Custom AI Chatbots From Your Business Data in Minutes
Aura
Search & Discovery
Intelligent Digital Safety for the Whole Family
hCaptcha
Code Assistance
Privacy-first bot protection
About the Author

Albert Schaper is a co-founder of Best-AI.org. He focuses on product strategy, AI adoption, practical tool selection, and educational content that helps users compare AI products with clearer context.
More from AlbertWas this article helpful?
Found outdated info or have suggestions? Send us a note.