Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

311–320 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#311

Earlier quoted context omitted.

> I can’t remember the word for “prosocial through lowering cost to zero” is but sometimes that too. Wiktionary: Benevolent, altruistic, unselfish, beneficent, philanthropic, selfless

Philanthropic! Thanks.

[deleted]

Re: Curl will not accept vulnerability reports during July 2026

#312

Earlier quoted context omitted.

I liked the idea as well, maybe OSS should adopt 6 months availability and 6 months for enterprise support schedule. This way both could benefit, OSS gets more funding, enterprise gets support (cheaper than hiring full-time employee for specific OSS)

nice idea to time vacation in the summar, right around major security conferences (blackhat, defcon, etc), when large bulk of CVEs get published, to put some fire under the enterprise butts

Private disclosures happen well before the presentations.

Re: Curl will not accept vulnerability reports during July 2026

#314

Earlier quoted context omitted.

Right, but nobody actually uses curl as the end destination, right? You use it to download something so that you can run another tool on it. And as such, you need to already be sandboxing the tool (since it processes untrusted data you received over the internet).

How would sandboxing curl help with vulnerabilities in your pdf reader?

Obviously, you need to sandbox all tools in the chain that handles untrusted data. This is security 101 stuff

Re: Curl will not accept vulnerability reports during July 2026

#315
post #98

Earlier quoted context omitted.

Yeah, I have seen several people who are completely shadowbanned (all comments dead) without any visible reason. There seems to be no way to report this.

Just email hn@ycombinator.com and Dang will look into it. He responds quick and will always address any concerns.

Yeah, I will try, I just came about another one: https://news.ycombinator.com/submitted?id=asxndu

Re: Curl will not accept vulnerability reports during July 2026

#316

Earlier quoted context omitted.

> Turns out they're as human as software engineers. Lawyers start out as humans but something about going into law school and then private practice, and feeding them after midnight turns them into... something else entirely.

Arguably the same is true for some software engineers. One minute they're a good friend that you respect, next thing you know they're building killbots or AI non consensual porn generators or surveillance platforms that are illegal for government agencies to operate. Perhaps it happens more often to lawyers?

Water is a key ingredient to the transformation. Nerds are less likely to shower than bougie lawyers, so we transform less often.

Re: Curl will not accept vulnerability reports during July 2026

#317
post #301

Earlier quoted context omitted.

Here I was thinking that cURL's (non-existent) enterprise support contracts were a polite way to tell brain-dead paper pushers to GTFO: https://daniel.haxx.se/blog/2022/01/24/logj4-security-inquir...

https://curl.se/support.html What do you mean by non-existent?

The paper pusher didn't have a contract.

Re: Curl will not accept vulnerability reports during July 2026

#319
post #233

Earlier quoted context omitted.

Doing the fix yourself is almost always the easy part. Disclosing it and getting a patch shipped across the entire Internet is the hard part.

Why would you personally need the entire internet to receive a fix?

I'm thinking of something on the order of Heartbleed. Sure, you fix it in your own servers. Are you sure you're ok with the entire Internet being vulnerable for two months? You don't have any data stored on servers that are outside of your control?

Re: Curl will not accept vulnerability reports during July 2026

#320

Earlier quoted context omitted.

Mythos found only one. Would have to be pretty serious bad guys. https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...

Remember though that many other AIs had already run and found issues that were fixed. If you had a time machine and took Mythos back a year it probably would have found a lot more. (if anyone has access to mythos it wouldn't be hard to test - download a release from last year and check)

> if anyone has access to mythos it wouldn't be hard to test - download a release from last year and check

Mythos might have seen last years bug reports so that might be cheating, kind-of. Bug reports ought to be great study material for LLM training.

Post reply on HN