The pressure

Simon Willison's Blog News

Summary

Daniel Stenberg describes the unprecedented pressure on the curl project due to a deluge of credible AI-assisted security reports, which have quadrupled the rate of incoming reports and increased the workload, while noting that most vulnerabilities found are low or medium severity.

No content available
Original Article
View Cached Full Text

Cached at: 05/27/26, 02:48 AM

# The pressure Source: [https://simonwillison.net/2026/May/26/the-pressure/](https://simonwillison.net/2026/May/26/the-pressure/) 26th May 2026 \- Link Blog **[The pressure](https://daniel.haxx.se/blog/2026/05/26/the-pressure/)**\([via](https://lobste.rs/s/dw02ye/pressure)\) Daniel Stenberg on the unprecedented level of pressure the`curl`team are facing right now thanks to the deluge of \(credible\) AI\-assisted security issues being reported\. > The rate of incoming security reports is 4\-5 times higher than it was in 2024 and double the speed of 2025 \-\- meaning that**on average we now get more than one report per day**\. The quality is way higher than ever before\. The reports are typically*very*detailed and long\. \[\.\.\.\] For the first time in my life, my wife voiced concerns about my work hours and my imbalanced work/life situation\. I work more than I’ve done before, but the flood keeps coming\. \[\.\.\.\] This is a never\-before seen or experienced pressure on the curl project and its security team members\. An avalanche of high priority work that trumps all other things in the project that is primarily mental because we certainly*could*ignore them all if we wanted, but we feel a responsibility, we have a conscience and we are proud about our work\. The good news is that`curl`is a very solid piece of software, so the vulnerabilities people are finding tend not to be of high severity: > What is also a good trend: almost no one finds*terrible*vulnerabilities\. All vulnerabilities found the last few years in curl have*all*been deemed severity LOW or MEDIUM\. I'm not saying there won't be any more HIGH ever, but at least they are rare\. The[most recent severity high curl CVE](https://curl.se/docs/CVE-2023-38545.html)was published in October 2023\.

Similar Articles

The pressure

Lobsters Hottest

Daniel Stenberg reflects on the pressure of maintaining the curl open-source project, discussing the relentless work on security, scrutiny, and the impact of AI-generated bug reports.

Mythos finds a curl vulnerability

Lobsters Hottest

Daniel Stenberg reports that Anthropic's Mythos AI model identified a vulnerability in curl, highlighting the growing role of advanced AI in security auditing while noting initial access hurdles via the Linux Foundation.

Bug bounty businesses bombarded with AI slop

Ars Technica

Bug bounty programs are being overwhelmed by a surge of low-quality AI-generated vulnerability reports, forcing platforms like HackerOne and Nextcloud to implement new filtering and validation measures. While the volume of submissions has jumped 76%, the rate of legitimate findings remains steady at 25%.

Scaling security with responsible disclosure

OpenAI Blog

OpenAI publishes an Outbound Coordinated Vulnerability Disclosure Policy outlining how it responsibly reports security vulnerabilities discovered in third-party software, anticipating increased vulnerability detection as AI systems become more capable at finding and patching security issues.