TL;DR
During July 2026, the curl project will not accept any vulnerability reports, creating a temporary gap in security oversight. The curl team will pause their Hackerone submission form and will not process security emails during this month.
✦ Why It Matters
Engineers should be aware of this hiatus to plan their vulnerability reporting around it.
Key Takeaways
Full Summary
The curl project, a widely used command-line tool for transferring data with URLs, has announced a planned break from handling vulnerability reports in July 2026, termed the 'curl summer of bliss.' During this month, the project's Hackerone submission form will be inactive, and security-related emails will not be addressed.
This decision aims to provide the team with a much-needed break while ensuring that users are aware of the temporary halt in security reporting. After July, the submission process will resume on August 3, 2026.
This pause highlights the importance of clear communication regarding security practices and timelines. Engineers and researchers should plan their vulnerability reporting accordingly to avoid delays.
Related