Curl will not accept vulnerability reports during July 2026

Hacker News Top News

Summary

The curl project will temporarily stop accepting vulnerability reports during July 2026 for maintainer rest, pushing the next release to September 2, 2026.

No content available
Original Article
View Cached Full Text

Cached at: 06/15/26, 08:56 AM

# curl summer of bliss Source: [https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/](https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/) ![](https://daniel.haxx.se/blog/wp-content/uploads/2026/06/curl-summer-of-bliss.jpg) **The curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026**\. We call it the*curl summer of bliss*\. curl’s[submission form on Hackerone](https://hackerone.com/curl)will be paused starting July 1, 2026\. ![](https://daniel.haxx.se/blog/wp-content/uploads/2021/04/closed-sign.png) Summer of bliss starts:**July 1, 2026**\. 00:00 CEST Submissions resume:**August 3 2026**\. 09:00 CEST The security email address will also be a dead end, as we will not process or otherwise care about security or vulnerability reports sent to us that way either\. Whatever issue you find that you feel a need to report to the curl project during this month has to wait\. curl’s Hackerone form opens for submissions again on Monday August 3\. We do not accept vulnerability reports over email in general, and this fact remains during and after our vacation\. ## Vacation for real ![](https://daniel.haxx.se/blog/wp-content/uploads/2026/06/fotografierende-ice-cream-3389010_1280.jpg) The curl maintainers will use this time of less pressure to take in some extra air and to enjoy the summer\. Maybe stroll outside a bit more\. Breath\. Some of us may spend some of this time to see other places\. We may get some extra time to spend on fixing bugs or working on new code\. Fun stuff\! ## Side\-effects As a direct side\-effect of this summer of bliss, to allow us some more time to handle the issues that might have piled up for us in early August,**we also push the release date**of 8\.22\.0 two weeks into the future\. Now scheduled to happen on September 2, 2026\. ## Vulnerability rate As previously mentioned, we have been under a huge[pressure](https://daniel.haxx.se/blog/2026/05/26/the-pressure/)for the last four months or so\. Now we need some rest\. We do not expect this deluge to be over\. ## GitHub curl’s[issue](https://github.com/curl/curl/issues)and[pull\-request](https://github.com/curl/curl/pulls)trackers on GitHub remain open and active like normal\. ## You too? If you and your Open Source projects also want to participate in the summer of bliss 2026: just do it and let us know\! I would of course encourage you to do so\. To take care of yourself as a top priority\. ## The bad guys won’t rest Probably not\. But we will\. ## But what if there is an emergency Then we get to read about it in August\. Or you get a[support contract](https://curl.se/support.html)and we get to read about it earlier\. ## Contracts excluded Everyone with a paid support contracts will of course still get full and appropriate service even during this period\. ![](https://daniel.haxx.se/blog/wp-content/uploads/2026/06/relaxed-2000.jpg)Daniel, in a relaxed state\. ## Credits The ice cream image was made by[fotografierende](https://pixabay.com/users/fotografierende-4558536/?utm_source=link-attribution&utm_medium=referral&utm_campaign=image&utm_content=3389010)from[Pixabay](https://pixabay.com//?utm_source=link-attribution&utm_medium=referral&utm_campaign=image&utm_content=3389010) ## Discussed On[hacker news](https://news.ycombinator.com/item?id=48537165)\. ## Post navigation ## curl, open source and networking

Similar Articles

Mythos finds a curl vulnerability

Lobsters Hottest

Daniel Stenberg reports that Anthropic's Mythos AI model identified a vulnerability in curl, highlighting the growing role of advanced AI in security auditing while noting initial access hurdles via the Linux Foundation.

The pressure

Simon Willison's Blog

Daniel Stenberg describes the unprecedented pressure on the curl project due to a deluge of credible AI-assisted security reports, which have quadrupled the rate of incoming reports and increased the workload, while noting that most vulnerabilities found are low or medium severity.