Skip to content
The open-source project curl has announced an unusual 'summer break,' suspending ...

The open-source project curl has announced an unusual 'summer break,' suspending ...

Gigazine June 16, 2026

The development team for the data transfer tool 'curl' has announced that it will temporarily suspend the acceptance and response to vulnerability reports starting July 1, 2026. This is due to the increased burden on developers from responding to a large number of reports. Report acceptance is scheduled to resume on August 3. curl summer of bliss | daniel.haxx.se

Even if a vulnerability is discovered during the holiday period, ordinary reporters will have to wait until HackerOne resumes accepting reports. On the other hand, general bug reports and code fix suggestions unrelated to vulnerabilities can still be submitted using GitHub Issues and Pull Requests as before. Development work is not being completely halted, and some developers may still use their time to fix bugs or write new code. To allow time to address pending cases after vulnerability reporting resumes, the release date for curl 8.22.0 has been postponed by two weeks from its original schedule to September 2, 2026. In response to a question whether malicious attackers don't take summer vacations, Stenberg replied to the effect that 'they probably don't, but we do.'

Please note that customers with paid support contracts will receive services as usual during the holiday period.

Jun 16, 2026 19:00:00 in Software , Security , Posted by log1d_ts

Extracted Entities

Domains (1)