
The curl project will not accept vulnerability reports for the entire month of July, its maintainers announced Monday, calling the break a “summer of bliss” aimed at escaping the relentless pressure of AI-generated security submissions (Daniel Stenberg blog; LWN.net).
The HackerOne submission form will be paused starting July 1. The project’s security email address will also be a dead end. Reports resume on August 3. Curl’s GitHub issue and pull request trackers will remain active and open as normal.
The decision is the culmination of a years-long deterioration in the quality of vulnerability reports the project receives. In January 2026, curl ended its bug-bounty program entirely, citing an “explosion in AI slop reports” that overwhelmed maintainers. The confirmed vulnerability rate, which had held above 15 percent for the program’s first five years, dropped below 5 percent in 2025 as AI-generated submissions flooded in.
Daniel Stenberg, curl’s lead developer and maintainer, described the toll in a May 2026 post. “The never-ending slop submissions take a serious mental toll to manage and sometimes also a long time to debunk,” he wrote. “Time and energy that is completely wasted while also hampering our will to live.”
What Changes
The HackerOne submission portal will close from July 1, 2026, at 00:00 CEST until August 3, 2026, at 09:00 CEST. The project’s security email will also not be monitored during that period. Anyone who finds a vulnerability during July must wait until August to report it.
The one exception: organizations with paid curl support contracts can still report issues through their contractual channels.
As a direct side-effect of the break, the release date for curl 8.22.0 has been pushed back by two weeks, now scheduled for September 2, 2026.
Maintainer Burnout in Open Source
Curl is one of the most widely used software libraries on the internet, present in almost every operating system, embedded device, and web server. Its security has implications for billions of devices. But the scale of that responsibility, combined with the volume of low-quality AI-generated reports, has pushed the small team of volunteer maintainers to a breaking point.
Stenberg’s announcement explicitly encouraged other open source projects to do the same. “If you and your Open Source projects also want to participate in the summer of bliss 2026: just do it and let us know,” he wrote. “To take care of yourself as a top priority.”
His closing line captured the tension: “The bad guys won’t rest. Probably not. But we will.”
Sources: Daniel Stenberg blog (June 15, 2026); LWN.net (June 15, 2026); Daniel Stenberg blog (January 26, 2026); Daniel Stenberg blog (May 26, 2026)

