10 ms·
Curl will not accept vulnerability reports during July 2026
- ubanholzer 4mo agoThis is great. Good decision.
- a13n 4mo agowhat a fantastic advertisement
- vortegne 4mo agoWish them nothing but good rest!
- flaburgan 4mo agoI can only applause this decision. Maintainers of FOSS project are constantly overwhelmed with close to 0 reward and with LLMs now the management of merge requests exploded even further. The fact that they actually keep providing support to paying users is enough.
- zarzavat 4mo ago> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.
- donw 4mo agoThat was just a beautiful, period.
- Timshel 4mo agoEspecially since it appears there is a solution if you truly need a fix. > Or you get a support contract and we get to read about it earlier.
- bawolff 4mo ago> Especially since it appears there is a solution if you truly need a fix. If you ever really need anything fixed in the open source world, there is always the option of doing it yourself
- alibarber 4mo agoYes - and realistically, if you're $BIGCO who's shipped a billion devices with some obscure curl vulnerability you just discovered, then the hard part is going to be rolling out a patch to all of them anyway, which is still a 'you' problem.
- matthewdgreen 4mo agoDoing the fix yourself is almost always the easy part. Disclosing it and getting a patch shipped across the entire Internet is the hard part.
- layer8 4mo agoWhy would you personally need the entire internet to receive a fix?
- Natsu 4mo agoI worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.
- Cider9986 4mo agoMythos found only one. Would have to be pretty serious bad guys. https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/ https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...
- bluGill 4mo agoRemember though that many other AIs had already run and found issues that were fixed. If you had a time machine and took Mythos back a year it probably would have found a lot more. (if anyone has access to mythos it wouldn't be hard to test - download a release from last year and check)
- timeinput 4mo agoImagine the bugs you'd find in curl from five years ago! I bet there are tons!
- etn_se 4mo ago> if anyone has access to mythos it wouldn't be hard to test - download a release from last year and check Mythos might have seen last years bug reports so that might be cheating, kind-of. Bug reports ought to be great study material for LLM training.
- bvcp 4mo agoif a company has a problem with this pay for support if its not worth the money …
- victorbjorklund 4mo agoPretty sure if you find a zero day in a software like that you don’t wait until a certain month.
- Scroll_Swe 4mo ago>A pleasant dose of humanity in decidedly inhuman times. As opposed to when? Do tell. I see this crap so much online. You just want an excuse to give up and be a victim. I hear it online and irl. You young people are broken, broken yet you have everything. How old are you, and where do you live? Life is better now than ever. I in Sweden can buy everything, access everything, and I own my apartment. Problem? As opposed to what? WW1? WW2? Vietnam war and corrupt nixon? The cold war when Russians accidentally invaded Sweden? Nuclear bomb fear? the 90s debt crisis? 90s balkan war? And refugee crisis? 9/11 and all that? 2015 refugee crisis? When? What do you compare to? The truth is, life is getting better. All the time. We had 10% unemployment in 2016 and even worse in 2008 when I graduated. Grow up.
- maxbond 4mo agoAtlas shrugged, but only for a month. I kid, it's well deserved. I do worry about their contract work loophole - if people disclose vulnerabilities publicly, their clients may pressure them to ship a fix anyway.
- Cider9986 4mo agoWhy was this dead?
- fc417fc802 4mo agoI've been noticing an unusual number of spuriously dead comments from accounts in good standing for a while now. My suspicion is false positives due to holding back the AI wave yet some of the casualties really don't seem to make any sense.
- maxbond 4mo agoTo be honest I don't think my account is in 100% good standing, but I can't say for certain. There's definitely some dead comments on my account that are deserved and I think there are some small limitations that are or have been placed on it (probably fairly). Mostly around flagging and vouching.
- inigyou 4mo agoI think that if you get a certain number of comments flagged or downvoted within a certain time window, your account gets flagged as a spammer and has a permanent rate limit applied. Above another threshold, it gets shadowbanned. I think the length of the account's history is also relevant. But https://en.wikipedia.org/wiki/Apophenia https://en.wikipedia.org/wiki/Apophenia
- cubefox 4mo agoYeah, I have seen several people who are completely shadowbanned (all comments dead) without any visible reason. There seems to be no way to report this.
- intronic 4mo agodown-under says: enjoy your summer :)
- dist-epoch 4mo ago[flagged]
- deleted 4mo ago[deleted]
- maxbond 4mo agoIt's massive and complex codebase. From the looks of it, pretty much what you'd expect, lots of chores, work on the test suite, keeping docs up to date, bug fixes. I didn't see any new features on my light skim but I'm sure they land occasionally. https://github.com/curl/curl/commits?author=bagder https://github.com/curl/curl/commits?author=bagder
- 0x1ceb00da 4mo agoThe entire http, http2, http3, tls, sftp spec for every operating system.
- ozim 4mo agohttps://curl.se/libcurl/ https://curl.se/libcurl/ Let me Google that for you. supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, MQTTS, POP3, POP3S, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. libcurl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, HTTP/2, HTTP/3, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, Kerberos), file transfer resume, http proxy tunneling and more! libcurl is highly portable, it builds and works identically on numerous platforms, including Solaris, NetBSD, FreeBSD, OpenBSD, Darwin, HPUX, IRIX, AIX, Tru64, Linux, UnixWare, HURD, Windows, Amiga, OS/2, BeOs, macOS, Ultrix, QNX, OpenVMS, RISC OS, Novell NetWare, DOS and more...
- nubinetwork 4mo agoI think the argument was that curl is fairly feature complete (as shown by your list), is there really that many bugs in curl that require immediate attention?
- patates 4mo agoFor the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but it was that bad for me. Signed: Former workaholic.
- donw 4mo agoAs a manager, I will quite literally ding people for working when they are supposed to be off. Work during work time, don't work during not-work time. Good practices mean that everyone is important, but nobody is irreplaceable, the team and the work will move along a little slower, but that's fine.
- laszlojamf 4mo agoas much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilight zone that isn't good for anybody. And it surprises - and saddens - me that not even friggin curl has the financial muscles to have somebody on-call for one month...
- necovek 4mo agoYou'd be surprised to learn this about free and open source software, but if a maintainer is unavailable, you have both full rights and full source code to... wait for it... fix it yourself (or pay someone to)! There is something unhealthy in this relationship only if you project "no warranty" into unrealistic expectations.
- ValdikSS 4mo agoThis is true for the majority of open-source projects, but the most serious ones, on which a lot of software/businesses/infrastructure depends, are controlled by foundations or some kind of other management entity. cURL also offers paid support and also paid access to the rock-solid (LTS) version, with guaranteed response times, and the blog post states that there's still people to respond to these.
- IshKebab 4mo agoYou don't really though. Sure you can fork it and fix your issue, but then what? Are you going to maintain your fork in perpetuity? Are you going to patch all the software that depends on the code you fixed to use your version instead of upstream? Are you going to get your users to do that too? In most cases this is extremely impractical.
- spiffyk 4mo ago> but then what? Then you send the patch upstream, they incorporate and maintain it for you. Congratulations, you just FOSSed.
- rustyhancock 4mo agoA curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)
- MatthewWilkes 4mo agoI think very few people would consider that to be responsible disclosure. The common practice is to allow 90 days as a minimum.
- rustyhancock 4mo agoI think I'd personally develop a minimal patch and then publically disclose. I'm not sure it's be reasonable to leave an actively exploited critical bug until August. Nor would I be too interested in playing middle man or paying for support from curl to get it out.
- zamadatix 4mo agoDisclosing an actively used exploit is is usually not treated the same as a typical vulnerability report.
- akerl_ 4mo agoReminder that what you're describing is "coordinated disclosure", and that there are in fact plenty of people who consider "full disclosure" to be preferable in some or all cases.
- cmxch 4mo agoJust publish early due to a documented lack of cooperation. They don’t have to answer, but you dont have to wait. Naturally some people find that this offensive since this puts a price to that “bliss”.
- Dylan16807 4mo agoTaking 1/3 of the standard time budget to get back to you isn't ideal, but it's not "a documented lack of cooperation". And if you find something halfway through the month then oh no two weeks to reply, that's basically a standard business interaction at that point.
- low_tech_love 4mo agoI read one sentence into this and knew directly that the developer must’ve been Swedish!
- robin_reala 4mo agoFor people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break. (See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/svensk-forfattningssamling/semesterlag-1977480_sfs-1977-480/#P12 https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven...)
- low_tech_love 4mo agoNot only that but the vacation is real. If someone is off then you should not expect them to answer at all (because if you do you’ll get very disappointed).
- mrweasel 4mo agoThis might not be true for Sweden, but Denmark have an interesting rule that makes contacting people in their vacation fairly expensive. If I'm asked to change my plans, my employer needs to compensate me financially. If you get a call and need to work for 30 minutes, then you are entitled to a full replacement day, not just the 30 minutes. For some jobs, interrupting people on vacation simply isn't allowed.
- stavros 4mo agoI work for a UK company and most people take basically all of August off (I end up with two months of vacation days a year so I take August off and sprinkle some leave around the year) and I can confirm that taking a month off is great. You forget what it's like to work, really.
- jdsnape 4mo ago
- okeuro49 4mo ago> Everyone with a paid support contracts will of course still get full and appropriate service even during this period.
- tempay 4mo agoFor anyone who thinks this might matter for security: * curl is mature enough that the chance of an impactful bug is basically zero * if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co * if there is such a bug, it's more important that it gets patched in package managers and rolled out. Upstream releases can wait.
- veltas 4mo ago> if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co No, that is the point, they are not going to accept your vuln report. They are taking a holiday.
- Sharlin 4mo agoExcept if you pay them for a support contract. So there is a way, and it's actually a pretty obvious way.
- chaz6 4mo agoI wonder if the likes of Red Hat, SuSE and Canonical have a support contract as they are commercial redistributors.
- inigyou 4mo agoProbably not. Why pay someone who's willing to work for free? When he stops working for free, then you pay him. Open source is not exempt from economic principles.
- squigz 4mo agoThere's a pretty big difference between a random report submitted via email, and, say, a close friend of the maintainers letting them know a serious vuln was found and they should login.
- 4mo ago
- NietTim 4mo agoProperly euromaxxing, this is the way.
- vessenes 4mo agoThe headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!
- plantain 4mo agoIt's an extremely un-European approach. European companies normally ignore their paid customers too from May to August.
- prmoustache 4mo agoignore is not the right word.
- limaoscarjuliet 4mo agoIn Poland smaller companies tell you outright: this and that person is on vacation, but plese call back in 2 weeks. Bigger companies will often ignore you and drag your problem through the vacation time.
- prmoustache 4mo ago> tell you outright That is not ignoring but announcing a delay. Bigger companies may have only limited number of people checking the mailboxes in july and august, that doesn't excuse not sending a small reply announcing delays but I guess they take it so much for granted they don't realize other continents aren't used to those kinds of delays. However in May and June every company is totally operational ( that doesn't mean nobody take holidays ). If you request something to one named person, that sole person can have scheduled holidays, parental or medical leave any time of the year. If it is a team mailbox, you should get an answer.
- embedding-shape 4mo ago
- fnoef 4mo agoBased! Amazing approach, enjoy the vacation!
- cat_plus_plus 4mo agoSGTM, if I am worried about a curl exploit, I will type details into Zoo Code prompt and it will disappear in about 30 seconds and then I can upload a PR for others concerned. Enjoy your vacation and I will enjoy security for a lot cheaper than an enterprise contract!
- napolux 4mo agoFunny, I have the same https://www.lafuma-mobilier.fr/ https://www.lafuma-mobilier.fr/ sunbed from the last pic. Also same color. :D
- eviks 4mo ago> Contracts excluded They aren't. If you ignore vulnerability report from an entity without a support contract, the vulnerability doesn't disappear just because the entities with support contracts are not aware of it
- shevy-java 4mo agoSo it is holiday season. I thought this was due to AI slop spam before I read the blog entry.
- davidgerard 4mo agoI heartily endorse the Fuck You Pay Me support process.
- lionkor 4mo agoHere's your reminder that 20-30 days paid vacation plus unlimited sick days (3+ days needs a doctor's note) is normal in Europe (e.g. Germany). If you get sick during vacation, you get those vacation days "refunded" back. If you suddenly are called in to work, somehow, during vacation, that time cannot be vacation time. You can't (generally) be fired without a notice period, resulting in job security to such a degree that ~6k in an emergency fund is plenty to be VERY secure, as you also get unemployment support otherwise anyway. Does this result in incompetent people not getting fired? No. You still fire them, you just have to deal with them another month after that. It's not a big price to pay. How is this all possible? Who subsidizes it? We all simply pay some % of our income to support this system. That's it. A couple percent, a couple bucks, and we get to basically never worry about starving or becoming homeless. You can have this, too, if you vote and protest and use democracy to make life better, not worse, for everyone.
- insumanth 4mo ago>> The bad guys won’t rest > Probably not. But we will. This is Exceptional. Perfect EuroMaxxing
- jimmyblanco 4mo agoGreat to see this stance
- panchtatvam 4mo agoAn evil way to extort money via support contracts.
- geraldcombs 4mo ago...so open source developers should know their place and just dedicate themselves to endless, unpaid toil forever and ever, amen?
- siskiyou 4mo agoIf you expect to get paid for doing a job, are you extorting your employer?
- dxxvi 4mo agoToday is Jun 15. So, I wonder if somebody + AI can rewrite curl in Rust in 1.5 months. I think it's possible if that person knows all curl features. However, does that person even exist?
- GoblinSlayer 4mo agohttps://curl.se/docs/security.html https://curl.se/docs/security.html - C bugs are marked.
- SoftTalker 4mo agoIf that were possible it would already have been done.
- dxxvi 4mo agoThere are projects like this: urlx, curlio.
- colinsane 4mo agocurl used to have rust in it, dropped it 1.5 yrs ago. AI doesn't help with the hard parts here i don't think. https://daniel.haxx.se/blog/2024/12/21/dropping-hyper/ https://daniel.haxx.se/blog/2024/12/21/dropping-hyper/
- steveklabnik 4mo agoThey dropped the hyper backend, but that wasn’t the only Rust code in tree.
- stogot 4mo agoGood for them & haxx!
- romaniv 4mo agoWhat this shows me (again) is that the whole system where vulnerabilities need to be constantly discovered, reported, analyzed, then patched, then the new version distributed to every singe user - again and again - is quite obviously unsustainable. The industry must come up with some alternative system for dealing with bugs and security issues. Currently the industry prefers to play dumb and turn its own failures into a profit (rent seeking) opportunity.
- jjice 4mo agoWhat's the better solution? Also, what's an example of this rent seeking in open source you're talking about?
- gpm 4mo ago> What's the better solution? IMO Writing correct software the first time around - so formal methods. But the tooling isn't there yet (though lightweight versions, e.g. strong type systems like rust's, are and significantly reduce the security issue load).
- fsflover 4mo agoI think you're right, and the solution is security through compartmentalization. See: https://qubes-os.org https://qubes-os.org.
- lofaszvanitt 4mo agoYeah, pay the foss maintainers. Anyone, who uses these projects must pay a minimum fee. Companies expected to pay a lot more.
- rurcliped 4mo agoWith more advance notice, someone could have found resources to fork curl with different vulnerability management expectations, e.g., "will not accept or otherwise handle any vulnerability reports during the month beginning 21 December 2026. We call it The Winter of Our Discontent."
- Havoc 4mo agoWhy is curl catching so many security issues? I can see something like nginx being in that spot but curl is primarily user initiated and pointed at a known target rather than internet facing accepting connections
- chopin 4mo agoIt presumably runs in a gazillion scripts.
- tredre3 4mo agocurl isn't more prone to security issues, it's just being talked about more. Daniel has an active blog, is active on social media, and interacts with the community. I don't think the nginx team has that presence, hence if they take a vacation or run mythos on their codebase or have an opinion about AI nobody really knows.
- deleted 4mo ago[deleted]
- spyc 4mo agoBoth libexpat ("Expat") and uriparser are following the curl security vacation and will not accept new vulnerability reports before 2026-08-01, starting today. [1] https://github.com/libexpat/libexpat/issues/1277 https://github.com/libexpat/libexpat/issues/1277 [2] https://github.com/uriparser/uriparser/issues/323 https://github.com/uriparser/uriparser/issues/323
- UltraSane 4mo agoIf employees are never truly unavailable then companies WILL become overly dependent on them.
- HardAnchor 4mo ago[flagged]