The cURL project’s maintainer Daniel Stenberg announced the termination of cURL’s vulnerability reward/bug bounty program after the security team was overwhelmed by a surge of low-effort, largely AI-generated vulnerability submissions that consumed maintainer time and created burnout risk. Stenberg stated the small open-source team could not keep up with the volume and warned that repeated low-quality submissions would lead to bans and public criticism, framing the decision as necessary to protect project sustainability and maintainer well-being.
Reporting indicates the change is being implemented via updates to cURL’s documentation (including BUG-BOUNTY.md) and will take effect at the end of January 2026, removing references to the project’s HackerOne program and stating that cURL will no longer offer rewards for reported vulnerabilities or assist researchers in obtaining compensation from third parties. The program had operated since 2019 via HackerOne and the Internet Bug Bounty, and the decision has raised concerns among users that eliminating bounties may reduce incentives for high-quality private reporting despite cURL’s widespread use across major operating systems and software stacks.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Starting February 1, 2026, cURL will stop taking new vulnerability reports through HackerOne and instead direct researchers to an internal reporting process via GitHub. Its updated security.txt states there is no monetary compensation and warns that low-quality reporters may be banned and publicly ridiculed.
cURL said it would continue accepting HackerOne security submissions through January 31, 2026, and would still process reports already in progress at that time. A pending update to BUG-BOUNTY.md removes references to HackerOne and confirms the end of rewards and third-party compensation help for new reports.
The cURL project officially announced via its GitHub repository that it would end its HackerOne bug bounty program because maintainers were overwhelmed by a surge of low-quality, often AI-generated vulnerability reports. The project said the small security team could no longer sustain the workload and needed to protect maintainer mental health and the project's long-term viability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.