Curl will not accept vulnerability reports during July 2026

The curl project has announced a 'summer of bliss' for July 2026, during which they will pause the acceptance of all vulnerability reports to allow maintainers to rest. The project will resume normal operations in August, and the release of version 8.22.0 has been delayed to September.
Why it matters
This highlights the growing issue of burnout in open-source software maintenance and the potential security implications of project-wide pauses in vulnerability reporting.
The curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026 . We call it the curl summer of bliss .
The article is a factual announcement regarding project operations and scheduling.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in