Skip to content
Tech News
← Back to articles

Curl will not accept vulnerability reports during July 2026

read original get Curl Security Update Guide → more articles
Why This Matters

The curl project will pause vulnerability reporting throughout July 2026 to allow maintainers to rest and focus on bug fixes and development. This temporary hiatus highlights the importance of balancing security responsiveness with developer well-being, especially in open-source projects. Consumers and industry stakeholders should be aware of this period to manage expectations regarding security disclosures for curl during this time.

Key Takeaways

The curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026. We call it the curl summer of bliss.

curl’s submission form on Hackerone will be paused starting July 1, 2026.

Summer of bliss starts: July 1, 2026. 00:00 CEST

Submissions resume: August 3 2026. 09:00 CEST

The security email address will also be a dead end, as we will not process or otherwise care about security or vulnerability reports sent to us that way either.

Whatever issue you find that you feel a need to report to the curl project during this month has to wait. curl’s Hackerone form opens for submissions again on Monday August 3.

We do not accept vulnerability reports over email in general, and this fact remains during and after our vacation.

Vacation for real

The curl maintainers will use this time of less pressure to take in some extra air and to enjoy the summer. Maybe stroll outside a bit more. Breath. Some of us may spend some of this time to see other places.

We may get some extra time to spend on fixing bugs or working on new code. Fun stuff!

... continue reading