The end of the #curl bug-bounty
daniel.haxx.se/blog/2026/01/26…
The end of the curl bug-bounty
tldr: an attempt to reduce the terror reporting. There is no longer a curl bug-bounty program. It officially stops on January 31, 2026.daniel.haxx.se
reshared this

Poolitzer
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Poolitzer • • •Poolitzer
in reply to daniel:// stenberg:// • • •happy to help. Now I can claim to have bug fixed curl.
...
Sort of
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •ulveon.net (on derg.social)
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to ulveon.net (on derg.social) • • •ulveon.net (on derg.social)
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to ulveon.net (on derg.social) • • •Poolitzer
in reply to daniel:// stenberg:// • • •talking about graphs maybe one showing the payout per month/year might be nice?
"The bugbounty cash"
daniel:// stenberg://
in reply to Poolitzer • • •curl - Project status dashboard
curl.sedaniel:// stenberg://
in reply to daniel:// stenberg:// • • •Poolitzer
in reply to daniel:// stenberg:// • • •Addison
in reply to daniel:// stenberg:// • • •Addison
in reply to Addison • • •HackerOne
HackerOnedaniel:// stenberg://
in reply to Addison • • •Frederik
in reply to daniel:// stenberg:// • • •I think if it does come to this, you might consider requiring a small donation to a charity? This would dramatically reduce the hassle on all sides, and do something good as a bonus.
daniel:// stenberg://
in reply to Frederik • • •Frederik
in reply to daniel:// stenberg:// • • •Graham Sutherland / Polynomial
in reply to daniel:// stenberg:// • • •josh g.
in reply to daniel:// stenberg:// • • •Sean McArthur
in reply to daniel:// stenberg:// • • •daniel:// stenberg:// reshared this.
Seth Larson
in reply to Sean McArthur • • •@seanmonstar Yep... I called for exactly this from platforms: sethmlarson.dev/slop-security-…
Primarily so that maintainers can collaborate against this sort of behavior, but also to make bad actors known.
New era of slop security reports for open source
sethmlarson.devdaniel:// stenberg://
in reply to Seth Larson • • •PhreakByte the Octopus
in reply to daniel:// stenberg:// • • •Torsten Curdt
in reply to daniel:// stenberg:// • • •without reading the article I knew why 😔
Maybe submitting a repot should cost something? The people that are confident about their findings would get the reward that easily pays for that. For the slop that's just too expensive.
Sounds weird but... maybe?
daniel:// stenberg://
in reply to Torsten Curdt • • •Torsten Curdt
in reply to daniel:// stenberg:// • • •Sorry, I was too quick with my reply 🫣
Yeah, I can see receiving a fee being a pain, too. Especially the uneven barrier to entry feels unfair.
Nini
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Nini • • •Lord Doctor Olle W
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to Lord Doctor Olle W • • •Mae
in reply to daniel:// stenberg:// • • •PressMind Labs: AI, technologie i przyszłość cyfrowego świata
PressMind Labs (PressMind Labs: AI, technologie i przyszłość cyfrowego świata)daniel:// stenberg://
in reply to Mae • • •