
curl will not accept vulnerability reports during July 2026
The curl project will not accept or process any vulnerability reports during July 2026 — its "summer of bliss". The HackerOne form pauses on July 1 and reopens on August 3, and release 8.22.0 slips to September 2.
The curl project will not accept or otherwise handle vulnerability reports during July 2026, in what its maintainers call the "curl summer of bliss". The submission form on HackerOne is paused from July 1, 2026, and reports sent to the project's security email address will not be processed either: curl does not accept vulnerability reports by email in general, and that does not change during or after the break.
The window opens on July 1, 2026 at 00:00 CEST, and submissions resume on Monday, August 3, 2026 at 09:00 CEST. Anything found in the meantime has to wait.
A release pushed back
One direct side effect is a schedule change: the release of curl 8.22.0 is pushed two weeks later, now scheduled for September 2, 2026, so the maintainers have time to work through whatever has piled up when the form reopens. The project has been under huge pressure for roughly four months, the post notes, and does not expect the flood of reports to be over.
What stays open
The pause applies to vulnerability reports only. curl's issue tracker and pull request queue on GitHub remain open and active as usual, and some maintainers may use the quieter period to fix bugs or work on new code. Anyone with a paid support contract still gets full service throughout July — including, as the post puts it, reading about an emergency earlier than August.
An invitation to other projects
The maintainers encourage other open source projects to hold their own summer of bliss in 2026, presenting rest as a priority rather than an indulgence: "The bad guys won't rest. Probably not. But we will."
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.