vulns.co
/
GKData.io MCP

curl project · 2 min read

curl Vulnerability Disclosure

curl project · HackerOne. Policy reviewed 2026-10-03. Live terms govern participation.

Open current policy Reviewed policy

Policy and restrictions

Preserve privacy, data integrity and availability; no disruption, spam or social engineering. Allow remediation before disclosure. Reports may become public after handling and sensitive-content review. Safe harbor is conditional.

Eligibility and submission status

Previously unreported, unpublished security issues in the latest released version qualify for review. AI assistance must be disclosed and its claims independently checked. Experimental features and most infrastructure issues are excluded.

A submission link is visible, but current acceptance was not independently established. Sources disagree on the reporting channel; no current migration or complete intake closure is asserted.

Advertised rewards

Current reports receive recognition rather than money. The former paid bounty ended January 31, 2026; that historical closure does not establish closure of disclosure intake.

Advertised schedules and exceptional ceilings are not individual award evidence.

Published scope snapshot

Captured 2026-10-03. Check the current policy for changes before participating.

In scope · 1 published rows
AssetTypeGroup / eligibility
https://github.com/curl/curlSOURCE_CODEBounty eligible: No
Out of scope · 0 published rows
AssetTypeGroup / eligibility
No rows captured. This does not establish that the program has no assets or restrictions.

Review limitations

  • The HackerOne policy displays May 13, 2026. Its updates page contains no updates; revision archives were not reviewed.
  • The January 26 announcement directed reports to GitHub or email. The current project policy instead directs them to HackerOne and rejects email reporting; browser review confirmed that discrepancy.
  • No age or residency rule was established. No account, submission or target interaction occurred. Full live terms prevail; this summary grants no authorization.
  • Only the project disclosure policy was refreshed for scope context; platform policy, updates and closure notices retain their earlier retrieval dates. No overall revision date or exhaustive exclusion coverage is asserted.

Sources and provenance

  1. curl public vulnerability-disclosure policy curl project / HackerOne · reviewed 2026-10-03
  2. curl vulnerability disclosure policy curl project · reviewed 2026-10-03
  3. The curl bug-bounty ends on January 31, 2026 curl project / Daniel Stenberg · reviewed 2026-10-03
  4. The end of the curl bug-bounty Daniel Stenberg, curl maintainer · reviewed 2026-10-03
  5. curl program updates curl project / HackerOne · reviewed 2026-10-03
  6. Former curl bug bounty page, redirected to disclosure policy curl project · reviewed 2026-10-03
  7. Published HackerOne structured scope curl project · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software