Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

51–60 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#51
post #26

A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)

Just publish early due to a documented lack of cooperation. They don’t have to answer, but you dont have to wait. Naturally some people find that this offensive since this puts a price to that “bliss”.

Taking 1/3 of the standard time budget to get back to you isn't ideal, but it's not "a documented lack of cooperation".

And if you find something halfway through the month then oh no two weeks to reply, that's basically a standard business interaction at that point.

Re: Curl will not accept vulnerability reports during July 2026

#52
post #29
post #3

> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.

I worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.

Mythos found only one. Would have to be pretty serious bad guys.

https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...

Re: Curl will not accept vulnerability reports during July 2026

#53

A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)

It would certainly be irresponsible.

The responsible thing would have been to simply wait another month, considering you've been warned about the delay.

Re: Curl will not accept vulnerability reports during July 2026

#54

I read one sentence into this and knew directly that the developer must’ve been Swedish!

For people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break. (See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven... )

Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave

  Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.

Re: Curl will not accept vulnerability reports during July 2026

#55
post #6

Atlas shrugged, but only for a month. I kid, it's well deserved. I do worry about their contract work loophole - if people disclose vulnerabilities publicly, their clients may pressure them to ship a fix anyway.

Why was this dead?

Re: Curl will not accept vulnerability reports during July 2026

#56

A curious approach, but I like it! Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)

Given that most of those users will not be capable of patching it directly, no, that seems like it would be irresponsible.

Re: Curl will not accept vulnerability reports during July 2026

#57

[flagged]

This is the HTTP/1.1 standard: https://datatracker.ietf.org/doc/html/rfc2616 Then there are also HTTP/2 and HTTP/3. That's just HTTP, curl supports 27 other protocols.

HTTP/1.1 - June 1999

It's not like the standard changed since curl was created

Re: Curl will not accept vulnerability reports during July 2026

#58
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering.

In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office.

Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resting and recovering.

Re: Curl will not accept vulnerability reports during July 2026

#59
post #33

[flagged]

https://curl.se/libcurl/ Let me Google that for you. supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, MQTTS, POP3, POP3S, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. libcurl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, HTTP/2, HTTP/3, cookies, user+password authentication (Basic, Digest, NTLM, Nego…

TIL it supports mqtt. Happy 10000 day to me :)
Post reply on HN