Skip to main content


Current #curl bug-bounty stats (since April 2019).

Reports: 475
Confirmed security issues: 73 (15%)
Identified bugs (but not security problems): 92 (19%)
Invalid: 310 (65%)

#curl
in reply to daniel:// stenberg://

I manage a bug bounty program where I work and the numbers look very similar

It's shocking sometimes the sheer amount of automated crap, low quality reports and bogus.

in reply to daniel:// stenberg://

65% invalid? How come? Are those a lot of rogue submissions, bogus CVE’s?
in reply to dtomvan

@dtomvan just people eager to get a bounty: "information exposure" claims on the website is common theme, but there are many variations of things that end up deemed neither a bug nor a security problem
in reply to daniel:// stenberg://

Like an integer overflow when passing --wait-timeout (is that the correct option?) being submitted as a high priority security problem?