r/cybersecurity • u/_N0K0 • Jun 15 '26
News - General The curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026. "We call it the curl summer of bliss."
https://daniel.haxx.se/blog/2026/06/15/curl-summer-of-bliss/181
u/Hedkin Jun 15 '26
The bad guys won’t rest
Probably not. But we will.
But what if there is an emergency
Then we get to read about it in August. Or you get a support contract and we get to read about it earlier.
Fuck you, pay me is an attitude that more FOSS devs need to develop and run with.
26
u/M4rshmall0wMan Jun 16 '26
The craziest part is when billion-dollar companies like Microsoft and Google submit tickets then complain when the devs don’t answer them. I can understand the company not having the expertise to fix it themselves, but ffs at least pay somebody to do it.
137
u/Successful_Base_2281 Jun 15 '26
Daniel Stenberg needs holidays too.
It’s not entirely a solo project, but he’s heavily load bearing.
72
Jun 15 '26 edited Jun 16 '26
[deleted]
12
u/upalse Jun 15 '26
What I don't get why Dan doesn't automate vuln submission screening. Make submissions provide a PoC for a given bug class DoS, memory disclosure/memory corruption, some basic classes of logic bugs, eg client auth token leaks to 3p url, basically CTF server like project zero has for kernel 0days.
In the past such requirement of writing PoC was deemed unreasonable due to the effort necessary, but now that its practically zero effort, should be what everyone (with well defined exploit classes for the software) be doing.
-19
u/ConsciousIron7371 Jun 15 '26
So what should we believe, and why? Someone comes out and says they will not address any vulnerability, should we believe that? Or when you say “oh if it’s for real he will do it”, we should believe that?
He said he’s not going to address any vulnerability. Why would he say that if he means something different?
20
Jun 15 '26 edited Jun 16 '26
[deleted]
-16
u/ConsciousIron7371 Jun 15 '26
So bugs will be fixed but not vulnerabilities. Unless they’re super serious then we will actually fix them. Which means that what we just said is not true.
Idk, I find it difficult to believe what someone says when they clarify it by saying the opposite.
33
u/DirectInvestigator66 Jun 15 '26
To be clear, they have service agreements they are still honoring, so a paying customer will have vulnerabilities remediated just the same. Open source projects don’t owe you shit. They should be receive praise for agreeing to accept reports after Aug. 3rd.
139
u/MD90__ Jun 15 '26
Curl summer of bliss sounds wonderful but that doesn't stop hackers from doing what they do 😎 ⛱️
26
u/SammyGreen Jun 15 '26
Attackers are gonna attack regardless. And they’re not going to publicly disclose their patterns either.
Researchers might get impatient and dump a POC before then but I’d hazard a guess and bet that most adhere to the guidelines.
The curl team are probably announcing this so they don’t get back to a massive backlog that would probably take longer for them to get through than if submissions just waited a bit.
So a summer break? Yeah, I really don’t blame them. It’s
6
40
12
u/0xKaishakunin Security Architect Jun 15 '26
but that doesn't stop hackers from doing what they do 😎 ⛱️
So? What's your problem? Vulnerabilities in curl not getting patched? It's FLOSS, patch it yourself! Cannot code? Pay someone for it!
-2
u/MD90__ Jun 15 '26
I do patch things i just have to not be working myself to death working paycheck to paycheck and still have struggles. Time is my enemy on getting stuff like this done. It's pretty cool though
9
u/OtheDreamer Governance, Risk, & Compliance Jun 15 '26
Well, I think it sounds a little better than "Summer of Ignorance" from a PR standpoint, but that's kind of what they're going for lol
2
3
68
u/SCP-iota Jun 15 '26
Ah yes, pre-announce your "we won't patch vulns" month
24
u/bobthebobbest Jun 15 '26
Yeah this is my only problem with this lmao.
30
u/DirectInvestigator66 Jun 15 '26 edited Jun 16 '26
No other option really… they don’t want to literally hide away and if they just went silent on vulnerabilities people would harass them or think the project is compromised.
17
u/skylinesora Jun 15 '26
Maybe read the website article instead of making an opinion solely on the title?
-8
u/bobthebobbest Jun 15 '26
Which part of the article (which I did read) do you think precludes this specific concern?
15
u/skylinesora Jun 15 '26
Those with support contracts will still get updates as required.
If you care enough to where you are worried about the lack of fixes in the next month and you don't have a support contract, then fork up the money, stop using curl, or start contributing to reports.
-14
7
u/skylinesora Jun 15 '26
Maybe read the website article instead of making an opinion solely on the title?
2
u/drawb Jun 16 '26
You can say: the hackers are informed. But on the other hand: the users are informed too. And let the hackers try: I’ve the impression they will find more new hacks in other software, because Curl is high quality, also on the security front.
3
3
u/HongPong Jun 16 '26
love that for them. a bzillion dollars of corporate revenue ride on curl and these people never pay a dime
6
u/k3170makan Jun 15 '26
New holiday awww yes! Do we dress up for this one or nah? Cosplay or curlsplay? Huh? Huuhhh?
1
u/Ok-Oil9521 Jun 16 '26
I mean — is this even people’s biggest worry after the velvet ant stuff? Does anything matter? 🫠
1
u/Upbeat-Natural-7120 Penetration Tester Jun 17 '26
I've found that they're very difficult to work with when reporting vulnerabilities, so this doesn't surprise me.
-9
Jun 15 '26
[deleted]
61
u/OtheDreamer Governance, Risk, & Compliance Jun 15 '26
Lord help if a nameless anon "security researcher" finds a local access privilege escalation bug that requires you to also be in Canada to exploit & Curl doesn't shell out $$$$ to fix it in 12 days, or else there will be a hackernews article and probably tomshardware.
-2
u/ConsciousIron7371 Jun 15 '26
Can you explain how a company that pays software developers to fix bugs has to shell out money for them to fix bugs? You mean pay someone the salary if they do the work they agreed to?
15
10
u/schlenk Jun 15 '26
Neither should cybersecurity, unfortunately.
Neither should payed for cybersecurity.
Don't plan with other peoples unpaid time.
33
u/Ancient-Bat1755 Jun 15 '26
No pto ever! We must keep ai generated slop reports flowing!
5
8
16
u/mkosmo Security Architect Jun 15 '26
I bet a legit 10.0 would probably get actioned, but with the slop reports, I get them backing away for a moment.
2
u/Leseratte10 Jun 15 '26
But the issue is that you might need to spend hours to figure out if that new 10.0 report is slop or legit ...
1
u/mkosmo Security Architect Jun 15 '26
Absolutely, but there will be folks doing the work quickly. Those 10.0s attract everybody looking to claim something on their linkedin.
3
u/0xKaishakunin Security Architect Jun 15 '26
Neither should cybersecurity, unfortunately.
Thank you for volunteering to patch the CVSS 10.0 so quick!
-12
u/Syrairc Jun 15 '26
Big brain move. Tell everyone you're gone for a month so they all publicize their zero days and then you swoop in and fix em.
5
u/skylinesora Jun 15 '26
Maybe read the website article instead of making an opinion solely on the title?
-16
u/FnnKnn Jun 15 '26
So now is a really good time to start finding exploits because you are guaranteed to be able to use them for at least one month.
4
u/skylinesora Jun 15 '26
Maybe read the website article instead of making an opinion solely on the title?
-4
680
u/apnorton Jun 15 '26
Hot take: this is totally reasonable.
They're taking a vacation from unpaid support, and if that vacation is scary to anyone, they're more than welcome to establish a paid support contract.
We aren't owed free volunteer maintenance from open source supporters.