The open source data transfer tool curl has patched 18 vulnerabilities this week, including a 25-year-old flaw that dates back to March 2001. The most notable issue, discovered by AI platform Mythos from Aisle, is a medium-severity authentication bypass vulnerability that could allow an attacker to reuse connections after client certificate settings had changed. While curl is used by over 30 billion devices worldwide, including servers, phones, and cars, there have been no public reports of these vulnerabilities being exploited in the wild.