Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Curl ended its paid HackerOne bug bounty in January 2026 after a surge in low-quality vulnerability reports that Daniel Stenberg, curl’s lead developer, described as largely AI-generated. But the project did not permanently leave HackerOne: it resumed using the platform for private vulnerability reports on March 1, without offering rewards. As of August 18, 2026, curl’s policy remains disclosure-only.
What curl actually shut down
The announcement concerned the paid bug bounty, not curl’s broader willingness to receive security reports. A bounty offers money for qualifying findings; a vulnerability-disclosure process gives researchers a way to report suspected flaws privately so maintainers can assess and address them. HackerOne can host that process without a bounty attached.
When Stenberg announced the change on January 26, he said the bounty would officially end January 31. Later accounts describe the shutdown as taking effect February 1. Curl briefly moved away from HackerOne, then returned to it as a reporting channel in March. The Internet Bug Bounty had helped fund rewards during the earlier program, but the new arrangement offers no payment for reports. Stenberg’s announcement and his February update explain the transition.
Why the bounty became unsustainable
Stenberg said the bounty had delivered real value, but that a rise in low-quality submissions made the work unsustainable for curl’s small security team. The core problem was not simply that some reports used AI. It was the flow of claims that appeared to be generated without enough independent checking.
#1 Best Overall
A security report is a request for expert investigation. Maintainers may need to reproduce the behavior, check affected versions and configurations, trace the relevant code, and decide whether the issue is exploitable or merely a bug. A confirmed vulnerability can then require a fix, private coordination, a CVE assignment and a public advisory. A false or unsupported claim still consumes time at the front of that process.
In that sense, a high volume of weak submissions can act like a denial-of-service problem: it competes with legitimate reports and ordinary development for scarce maintainer attention. Stenberg described the burden and the bounty’s end in his announcement.
The bounty had produced results before the reporting surge
The program was not a failure from the start. Stenberg said that between its launch in 2019 and its termination, it had led to 87 confirmed vulnerabilities and more than $100,000 in rewards. Those are figures reported by the project lead, not independently audited financial statistics. They show why the decision is better understood as a response to a changed cost-benefit balance than as a verdict that bounty programs have no value.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallHow curl’s policy changed in 2026
- January 26: Stenberg announced the end of the paid bounty, setting January 31 as its official end date.
- February 1: Later commentary describes the shutdown as taking effect.
- March 1: Curl resumed receiving security reports through HackerOne, with no rewards.
- April 22: Stenberg reported that low-quality submissions had largely disappeared, while report volume and the share of useful findings had risen.
- July 1–August 3: Curl paused ordinary vulnerability-report intake, then reopened submissions on August 3.
- August 18: The official policy still directed suspected vulnerabilities to HackerOne and offered no bounty.
The project’s disclosure policy gives the current route and expectations. Stenberg’s accounts cover the return to HackerOne, the April report-quality update, and the summer pause.
Why curl returned to HackerOne without restoring rewards
The platform and the incentive are separate choices. Curl briefly tried moving away from HackerOne, but Stenberg later said GitHub did not meet the project’s security-reporting needs. Returning to HackerOne preserved a private, structured intake and coordination channel; it did not reopen the bounty.
That distinction matters because a platform can help manage confidential reports and researcher communication, but it cannot guarantee that submissions are accurate. Nor does it remove the project’s responsibility to review them. Curl’s approach kept the reporting route while dropping the financial incentive it considered part of the problem.
AI assistance is not the same as an unverified report
Stenberg’s April account complicates the idea that the project was rejecting AI-assisted security work. He said AI use remained common, but the weak-report problem had largely faded after rewards ended. He described a period of “high-quality chaos”: report volume was roughly twice the 2025 rate, and the confirmed-vulnerability rate had returned to approximately 15–16%, which he characterized as around the pre-AI level. These are curl’s own observations, not an industry-wide measurement.
Recommended Free Tools
The practical dividing line is validation. A researcher may use AI to explore code or develop a hypothesis, then check it, understand the affected path and provide reproducible evidence. That differs from submitting model-generated speculation as a finding. A human-written report can also be wrong; authorship alone does not establish quality.
Curl’s policy does not ban AI. It asks reporters to avoid large, lazy AI-generated explanations and make reports clear and digestible. A useful report should distinguish a theoretical concern from an ordinary bug and a security vulnerability, explain impact without inflating severity, and give maintainers a way to reproduce the claim.
What researchers should do before reporting a curl vulnerability
Curl’s current policy directs suspected vulnerabilities to HackerOne, not the public bug tracker or ordinary email. The project handles reports privately until formal disclosure; published issues appear on its security advisory page.
- Identify the affected curl version and relevant configuration or platform.
- Explain the security impact and how it differs from a non-security bug.
- Provide precise reproduction steps or a proof of concept that you have tested.
- Describe the relevant behavior and evidence in concise, understandable terms.
- Do not expect a bounty or other payment for a report.
The July intake pause was a specific 2026 measure, not evidence that curl permanently closes submissions every July. During that pause, commercial support arrangements were treated separately from ordinary vulnerability reporting, as Stenberg explained in the summer announcement.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →What the episode means for open-source security
Curl is widely used as a command-line tool and software library, and assessing a security claim can involve protocol behavior, platform differences, authentication, proxies, TLS and memory safety. A small maintainer team has to balance that work against development and routine project operations.
Best Value
Stenberg later linked report pressure to fewer feature changes during the curl 8.21.0 development cycle. The June 24, 2026 release nevertheless included 18 security fixes, which he described as a project record for one release and for the number of vulnerabilities published in that calendar year at that point. The episode therefore shows both sides of the capacity problem: security findings can be valuable, and handling them can crowd out other work. Stenberg’s curl posts cover the release and workload.
Other projects could respond in several ways, each with trade-offs. Removing rewards may reduce bounty-driven low-effort submissions but can also deter independent researchers, including those who rely on bounty income. Reputation requirements or demonstrated proof-of-concept rules may improve the signal, but can raise barriers to new researchers. Rate limits, clear scope rules and dedicated triage can control workload, although each needs staff time and does not prevent all false positives. Automation can help deduplicate or classify reports; it should not substitute for human judgment on security impact.
For projects whose users depend on urgent maintainer attention, paid support contracts are another sustainability option, distinct from paying a bounty for a discovered flaw. They can fund support and response capacity, but are not a replacement for broad independent security research. Curl’s summer notice explicitly treated support contracts separately from the paused public intake.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

