curl Is Refusing Vulnerability Reports for an Entire Month
The curl project will pause all vulnerability report intake for July 2026. Behind the decision is an avalanche of security reports that pushed a small maintainer team to its limit.
On June 15, 2026, Daniel Stenberg posted an announcement on his blog with a title that stopped every security-conscious developer mid-scroll: "curl summer of bliss." The curl project is refusing vulnerability reports for the entire month of July 2026. The library installed on roughly 30 billion devices worldwide will not accept any new security submissions. The Hackerone submission form will be paused starting July 1. The security email address will be a dead end. Whatever vulnerability anyone finds in curl during those 34 days will have to wait until August 3.
The announcement was not a stunt, a protest, or a negotiation tactic. It was the logical endpoint of a four-month avalanche that pushed a small team of mostly volunteer maintainers past the point where continuing without a break would cause more harm than pausing. To understand why one of the most security-critical open source projects on the planet is stepping away from its inbox, you need to understand the numbers behind the decision.
The Numbers That Made This Necessary
In late May 2026, Stenberg wrote a post titled "The Pressure" that laid out the math. The rate of incoming security reports to curl was running at 4 to 5 times the 2024 level and double the 2025 rate. On average, more than one vulnerability report arrived every single day. The quality of those reports had also shifted. What used to be a mix of legitimate findings and noise, including the much-documented flood of AI-generated "slop" reports that plagued the project through 2025, had transformed into something harder to dismiss: detailed, well-researched submissions that demanded serious triage time per entry.
The result was visible in the numbers for curl 8.21.0, shipped on June 24. That single release contained 18 published CVEs, a new project record. Four were rated medium severity, covering issues like SASL double-free errors and cross-proxy Digest authentication state leaks. The remaining fourteen were rated low, spanning everything from trailing-dot domain supercookie bypasses to HTTP/2 stream-dependency tree use-after-free bugs. With about 30 CVEs already published in the first half of 2026, the projected yearly total pointed to at least double the previous annual record.
Behind every one of those CVEs is a process: verify the claim, assess the severity, determine when the bug was introduced, write a patch, produce a detailed advisory, and communicate back and forth with the reporter. When reports arrive faster than that process can run, a backlog forms. Having a growing list of potential security problems that you do not yet fully understand takes a mental toll that Stenberg described as unprecedented in curl's nearly 30-year history.
The Human Being Behind the Inbox
curl is not a company product. It has no parent organization, no umbrella foundation, and no dedicated security operations center. The security team is a handful of people, and the lead maintainer, Daniel Stenberg, has been working on curl since 1998. He works roughly 50-hour weeks, often seven days a week, because curl is both his full-time job and his spare-time passion. The project is personal to him.
In May, Stenberg wrote something that made the human dimension impossible to ignore: "For the first time in my life, my wife voiced concerns about my work hours and my imbalanced work/life situation." He added that people around him had begun asking how he was coping, and that he was concerned for his teammates. This is not the language of a security advisory. It is the language of someone who has been sprinting for months and is signaling that the pace is unsustainable.
The broader shift toward AI-native development patterns has been a double-edged sword for projects like curl. AI-assisted tools help researchers find vulnerabilities faster and produce more thorough reports. But the receiving end is the same small group of humans who were already stretched thin before the tools got better. The asymmetry between how fast vulnerabilities can be found and how fast a human team can triage, patch, and disclose them is growing wider every quarter.
What the Pause Actually Means
The mechanics of the pause are straightforward. curl's Hackerone submission form goes offline at midnight CEST on July 1, 2026. It reopens at 9 AM CEST on August 3. The security email address will not be monitored. Any vulnerability found during July will not be read, assessed, or acted upon until August. The regular GitHub issue and pull request trackers remain open for non-security work. The next release, curl 8.22.0, has been pushed two weeks to September 2 to account for the backlog that will accumulate during the pause.
There is one exception: organizations with paid support contracts will continue to receive full service, including security response, during the entire period. This detail matters. It shows that the pause is not about incapacity but about boundaries. The maintainers can still do the work. They are choosing not to do it for free, for one month, to preserve their ability to keep doing it for the next thirty years.
The timing is also deliberate. July is a quiet month in much of the software industry. Release cycles slow down. Many European developers take vacation. By pausing during a natural lull, the curl team minimizes the practical impact while maximizing the restorative value of the break. If you had to pick a month to step away from security reports without causing maximum disruption, July is the one.
The Bigger Picture: Who Maintains the Maintainers
The curl summer of bliss is not just a curl story. It is a case study in a structural problem that the software industry has been dodging for years. Critical open source infrastructure is maintained by individuals and small teams who are dramatically outnumbered by the users and dependents of their work. curl is installed in phones, cars, TVs, printers, game consoles, kitchen appliances, and virtually every server on the internet. Its security affects everyone. Yet the project's funding model relies on a small number of support contracts and the personal commitment of a few people.
The agentic AI trend adds a new dimension to this imbalance. AI agents can now autonomously fuzz code, generate test cases, and produce detailed vulnerability reports at a scale that no human research team could match. The speed of discovery has increased. The speed of remediation has not, because remediation still requires human judgment, architectural understanding, and careful patch writing. The pipeline between finding and fixing is the bottleneck, and the bottleneck runs on people.
Other projects are watching closely. If curl's pause works, if the maintainers come back in August recharged and the sky does not fall during July, it sets a precedent. Other overloaded maintainers might feel empowered to set similar boundaries. If it backfires, if a serious vulnerability goes unreported during July and causes real damage, the conversation will shift from "should maintainers take breaks" to "how do we fund enough maintainers so breaks are not necessary." Either outcome forces the industry to confront a question it has been avoiding.
What Happens After August 3
When the Hackerone form reopens, the curl team will face whatever backlog accumulated during July, plus the ongoing daily rate of new reports. Stenberg has been clear that he does not expect the flood to be over. The pause is a reset, not a solution. The structural problem remains: a critical piece of internet infrastructure is maintained by a handful of people who are outnumbered by the volume of security scrutiny directed at their code.
The developer experience conversation in 2026 has largely focused on tooling, workflows, and AI copilots. The curl summer of bliss is a reminder that the most important developer experience metric is whether the maintainers of the software you depend on are sleeping at night. Everything else is secondary.
Further reading: the curl summer of bliss announcement, the pressure post, and the curl 8.21.0 release notes on Daniel Stenberg's blog.
Rune AI
Key Insights
- The curl project is pausing all vulnerability report intake for the entire month of July 2026.
- Incoming security reports are running at 4 to 5 times the 2024 rate, averaging more than one per day.
- curl 8.21.0 shipped 18 CVEs, a project record, and 2026 is on track to double the previous yearly CVE count.
- The pause is a deliberate burnout prevention measure by a small volunteer maintainer team.
- The decision raises uncomfortable questions about how the industry sustains maintainers of critical infrastructure.
Frequently Asked Questions
Why is curl refusing vulnerability reports for July 2026?
The curl maintainer team has been under unprecedented pressure from a flood of vulnerability reports, running at 4 to 5 times the 2024 rate and averaging more than one report per day. The team is small and mostly volunteer. The July pause, called the 'curl summer of bliss,' is a deliberate break to prevent burnout and let maintainers recover before resuming in August.
Will real security vulnerabilities go unpatched during the pause?
Yes, any vulnerability reported during July 2026 will not be processed until August 3, 2026. The Hackerone submission form is paused, and the security email address will not be monitored. Daniel Stenberg has stated that if there is a genuine emergency, the team will read about it in August. Paid support contract holders still receive full service during the period.
How many vulnerability reports is curl getting right now?
The project is receiving more than one report per day on average. The curl 8.21.0 release in June 2026 included 18 published CVEs, a new project record. With about 30 CVEs already published in the first half of 2026, the projected yearly total is at least double the previous record.
Is AI contributing to the flood of reports?
Yes, indirectly. While Daniel Stenberg has noted that the quality of reports has improved significantly compared to earlier AI-generated 'slop' submissions, the increased accessibility of AI-assisted security research tools means more researchers can produce detailed, well-structured vulnerability reports. The volume has gone from manageable to overwhelming in a matter of months.
Conclusion
The curl summer of bliss is a canary in the coal mine for open source infrastructure. When the maintainers of software installed on 30 billion devices decide the only way to stay sane is to shut the door for a month, the ecosystem has a structural problem. The decision is not reckless. It is honest. A burned-out maintainer who quits is a bigger security risk than a 34-day pause on vulnerability intake. The lesson for every organization that depends on curl, and that is effectively every organization, is that critical open source infrastructure does not maintain itself. It runs on the mental health of a handful of people who have been doing this for decades, and they just told the world they need a break.