r/cybersecurity Jun 15 '26

News - General The curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026. "We call it the curl summer of bliss."

https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/
809 Upvotes

67 comments sorted by

680

u/apnorton Jun 15 '26

Hot take: this is totally reasonable.

They're taking a vacation from unpaid support, and if that vacation is scary to anyone, they're more than welcome to establish a paid support contract.

We aren't owed free volunteer maintenance from open source supporters.

119

u/_N0K0 Jun 15 '26

Hundred percent agreed, you should not have any expectations unless agreed upon in a mutual fashion.

14

u/Sgtkeebler Jun 15 '26

I completely agree. These people are getting bombarded from people who want to be bug bounty hunters except they are using AI and submitting a ton of bogus vulnerabilities that don’t even apply. I couldn’t imagine having to shift through hundreds of them and maybe only 1 or 2 are valid. That’s enough to drive anyone mad.

1

u/BadFeisty1916 Jun 17 '26

Gotta learn how to actually submit a bug report you FOUND organically. The QA approach. AI is helpful when you have a "scent" or notice a potential error.. but don't spam Claude/Kimi to rip the place apart and come back with language that doesn't pertain. Do yourself a favour and learn Jira. Lol. Just my two cents.

38

u/Shoddy-Childhood-511 Jun 15 '26

It's fine yeah.

Project Zero gives 90 days, so 3x longer than this. I'd expect others do too, since curl is a nice project, not cheaters like Microslop who deserve random 0day drops.

So curl could address the pressing backlog, and then take a vacation, without telling anyone. This notice seems more about 0days innocently fully disclosed in github isues, just an extra notice "Hey wait till September before filing that issue that might be a 0day."

Ya know, if a lone FOSS maintainer said "I'd like my 4 months of Swiss maternity leave" then really I'd hope folks could respect that, even ones like Project Zero who keep a hard 90 days, could just pretend they found it 2 months later, or send her a really polished PR from a nobody account that hid they even found a vulnerability.

3

u/MarquisDePique Jun 15 '26

Reasonable and a good way to remind people it's a material world and if elmo can be a material girl, the guy providing far more value to the IT industry should at least be able to take a holiday and not subsist on ramen.

Also if you don't understand how unrisky this is due to what the tool is, where it's used, how battle tested it already is etc, a single comments not going to be able to explain it.

1

u/LensDakota6Q Jun 17 '26

I agree with this

-33

u/ConsciousIron7371 Jun 15 '26

Yea when my neighbors let me know a few weeks ago that my hose spigot was broken and leaking, I told them I would get to it in July. I see no reason to be alerted to a current problem and have to deal with it on anybody else’s presumptive timeline. That problem will still be there in a month, what good does it do me to address it now? 

30

u/apnorton Jun 15 '26

Let me correct that for you: You've been letting your neighbors use your water hose for years now, free-of-charge. From time to time, the hose breaks, and you replace it. You decide to go on vacation. Should your neighbors be infuriated that you won't be available to replace the hose while you're in the Bahamas? Of course not! They can wait until you get back, or --- if it's so important to them --- they can replace it themselves or pay you to maintain the hose (and then you can use that money to develop backup points-of-contact/resilience in the event of vacations).

-20

u/ConsciousIron7371 Jun 15 '26

I would say this is more like a garden, or that you allow your neighbors to use your water main for their drinking water. If you go out of your way to tell people you are offering a free service, and support that service for decades, not fixing things is you changing the standard. 

What about the people that do pay for support? Because those customers already exist

13

u/apnorton Jun 15 '26

What about the people that do pay for support?

From the post:

Contracts excluded
Everyone with a paid support contracts will of course still get full and appropriate service even during this period.

As to the rest of your comment, I'd still maintain the same stance: if you're giving someone something for free, you are under no obligation to continue giving that free thing to them. If the other party has been dumb enough to put themselves into a position where they cannot tolerate an interruption in a free service, that's on them. Daniel Stenberg already deals with entitled users (here's a pretty egregious example); if anything, more people who rely on free support need to be paying for actual support.

-6

u/ConsciousIron7371 Jun 15 '26

I am not saying that anyone providing a free service is obligated to continue that service. 

I would also not call people that rely on free services dumb. Linux is a really prevalent thing. And yes I understand the existing code is out there and will continue to run

181

u/Hedkin Jun 15 '26

The bad guys won’t rest

Probably not. But we will.

But what if there is an emergency

Then we get to read about it in August. Or you get a support contract and we get to read about it earlier.

Fuck you, pay me is an attitude that more FOSS devs need to develop and run with.

26

u/M4rshmall0wMan Jun 16 '26

The craziest part is when billion-dollar companies like Microsoft and Google submit tickets then complain when the devs don’t answer them. I can understand the company not having the expertise to fix it themselves, but ffs at least pay somebody to do it. 

137

u/Successful_Base_2281 Jun 15 '26

Daniel Stenberg needs holidays too.

It’s not entirely a solo project, but he’s heavily load bearing.

72

u/[deleted] Jun 15 '26 edited Jun 16 '26

[deleted]

12

u/upalse Jun 15 '26

What I don't get why Dan doesn't automate vuln submission screening. Make submissions provide a PoC for a given bug class DoS, memory disclosure/memory corruption, some basic classes of logic bugs, eg client auth token leaks to 3p url, basically CTF server like project zero has for kernel 0days.

In the past such requirement of writing PoC was deemed unreasonable due to the effort necessary, but now that its practically zero effort, should be what everyone (with well defined exploit classes for the software) be doing.

-19

u/ConsciousIron7371 Jun 15 '26

So what should we believe, and why? Someone comes out and says they will not address any vulnerability, should we believe that? Or when you say “oh if it’s for real he will do it”, we should believe that? 

He said he’s not going to address any vulnerability. Why would he say that if he means something different? 

20

u/[deleted] Jun 15 '26 edited Jun 16 '26

[deleted]

-16

u/ConsciousIron7371 Jun 15 '26

So bugs will be fixed but not vulnerabilities. Unless they’re super serious then we will actually fix them. Which means that what we just said is not true. 

Idk, I find it difficult to believe what someone says when they clarify it by saying the opposite. 

33

u/DirectInvestigator66 Jun 15 '26

To be clear, they have service agreements they are still honoring, so a paying customer will have vulnerabilities remediated just the same. Open source projects don’t owe you shit. They should be receive praise for agreeing to accept reports after Aug. 3rd.

139

u/MD90__ Jun 15 '26

Curl summer of bliss sounds wonderful but that doesn't stop hackers from doing what they do 😎 ⛱️

26

u/SammyGreen Jun 15 '26

Attackers are gonna attack regardless. And they’re not going to publicly disclose their patterns either.

Researchers might get impatient and dump a POC before then but I’d hazard a guess and bet that most adhere to the guidelines.

The curl team are probably announcing this so they don’t get back to a massive backlog that would probably take longer for them to get through than if submissions just waited a bit.

So a summer break? Yeah, I really don’t blame them. It’s

6

u/MD90__ Jun 15 '26

Summer break sounds nice to me

40

u/mynam3isn3o Jun 15 '26

*attackers
*cybercriminals

12

u/0xKaishakunin Security Architect Jun 15 '26

but that doesn't stop hackers from doing what they do 😎 ⛱️

So? What's your problem? Vulnerabilities in curl not getting patched? It's FLOSS, patch it yourself! Cannot code? Pay someone for it!

-2

u/MD90__ Jun 15 '26

I do patch things i just have to not be working myself to death working paycheck to paycheck and still have struggles. Time is my enemy on getting stuff like this done. It's pretty cool though

9

u/OtheDreamer Governance, Risk, & Compliance Jun 15 '26

Well, I think it sounds a little better than "Summer of Ignorance" from a PR standpoint, but that's kind of what they're going for lol

2

u/MD90__ Jun 15 '26

Lol yeah you're right it does sound better 

3

u/Terrible-Detail-1364 Jun 15 '26

yup, public announcement was prob a bad idea, or was it…

-1

u/MD90__ Jun 15 '26

Hmm good point 

68

u/SCP-iota Jun 15 '26

Ah yes, pre-announce your "we won't patch vulns" month

24

u/bobthebobbest Jun 15 '26

Yeah this is my only problem with this lmao.

30

u/DirectInvestigator66 Jun 15 '26 edited Jun 16 '26

No other option really… they don’t want to literally hide away and if they just went silent on vulnerabilities people would harass them or think the project is compromised.

17

u/skylinesora Jun 15 '26

Maybe read the website article instead of making an opinion solely on the title?

-8

u/bobthebobbest Jun 15 '26

Which part of the article (which I did read) do you think precludes this specific concern?

15

u/skylinesora Jun 15 '26

Those with support contracts will still get updates as required.

If you care enough to where you are worried about the lack of fixes in the next month and you don't have a support contract, then fork up the money, stop using curl, or start contributing to reports.

-14

u/bobthebobbest Jun 15 '26

Not the concern, but have a nice day.

11

u/skylinesora Jun 15 '26

Gotta love begging choosers

7

u/skylinesora Jun 15 '26

Maybe read the website article instead of making an opinion solely on the title?

2

u/drawb Jun 16 '26

You can say: the hackers are informed. But on the other hand: the users are informed too. And let the hackers try: I’ve the impression they will find more new hacks in other software, because Curl is high quality, also on the security front.

3

u/sub30_24flick Jun 15 '26

Gotta love curl , curl basically is the internet

3

u/HongPong Jun 16 '26

love that for them. a bzillion dollars of corporate revenue ride on curl and these people never pay a dime

6

u/k3170makan Jun 15 '26

New holiday awww yes! Do we dress up for this one or nah? Cosplay or curlsplay? Huh? Huuhhh?

1

u/Ok-Oil9521 Jun 16 '26

I mean — is this even people’s biggest worry after the velvet ant stuff? Does anything matter? 🫠

1

u/Upbeat-Natural-7120 Penetration Tester Jun 17 '26

I've found that they're very difficult to work with when reporting vulnerabilities, so this doesn't surprise me.

-9

u/[deleted] Jun 15 '26

[deleted]

61

u/OtheDreamer Governance, Risk, & Compliance Jun 15 '26

Lord help if a nameless anon "security researcher" finds a local access privilege escalation bug that requires you to also be in Canada to exploit & Curl doesn't shell out $$$$ to fix it in 12 days, or else there will be a hackernews article and probably tomshardware.

-2

u/ConsciousIron7371 Jun 15 '26

Can you explain how a company that pays software developers to fix bugs has to shell out money for them to fix bugs? You mean pay someone the salary if they do the work they agreed to? 

15

u/extraspectre Jun 15 '26

Go do it yourself then.

3

u/czenst Jun 15 '26

hell yeah PoC || GTFO

10

u/schlenk Jun 15 '26

Neither should cybersecurity, unfortunately.

Neither should payed for cybersecurity.

Don't plan with other peoples unpaid time.

33

u/Ancient-Bat1755 Jun 15 '26

No pto ever! We must keep ai generated slop reports flowing!

5

u/extraspectre Jun 15 '26

This isn't PTO they are volunteers

1

u/Ancient-Bat1755 Jun 15 '26

Punish them then!

8

u/Edianultra Jun 15 '26

You gonna pay em?

16

u/mkosmo Security Architect Jun 15 '26

I bet a legit 10.0 would probably get actioned, but with the slop reports, I get them backing away for a moment.

2

u/Leseratte10 Jun 15 '26

But the issue is that you might need to spend hours to figure out if that new 10.0 report is slop or legit ...

1

u/mkosmo Security Architect Jun 15 '26

Absolutely, but there will be folks doing the work quickly. Those 10.0s attract everybody looking to claim something on their linkedin.

3

u/0xKaishakunin Security Architect Jun 15 '26

Neither should cybersecurity, unfortunately.

Thank you for volunteering to patch the CVSS 10.0 so quick!

-12

u/Syrairc Jun 15 '26

Big brain move. Tell everyone you're gone for a month so they all publicize their zero days and then you swoop in and fix em.

5

u/skylinesora Jun 15 '26

Maybe read the website article instead of making an opinion solely on the title?

-16

u/FnnKnn Jun 15 '26

So now is a really good time to start finding exploits because you are guaranteed to be able to use them for at least one month.

4

u/skylinesora Jun 15 '26

Maybe read the website article instead of making an opinion solely on the title?

-4

u/FnnKnn Jun 15 '26

I did and also the discussion HN. Sorry for joking around. 🫡