Skip to main content


In 2022 alone, the #curl project's bug bounty paid 30,000 USD in reward money.
#curl
in reply to daniel:// stenberg://

Is that because there was more money to pay rewards or because there was more bugs?
in reply to Jimmy Sjölund

@jimmysjolund In 2022 no less than 21 CVEs were registered in total for curl, which is the second busiest year so far. Because people are looking really hard to find the cracks. I blogged about it last year: daniel.haxx.se/blog/2022/08/22…