Daniel Stenberg, creator of the tool for sending and receiving data over the network curl, announced a suspension of the acceptance and processing of vulnerability reports from July 1 to August 3. An exception will be made only for senders using paid support. The reason cited is the need for a break and rest after a significant increase in the workload of processing vulnerability reports over the past four months.
Messages sent through the form on Hackerone and email security@curl.se during this time will not be considered. The option to submit pull requests and issue reports through GitHub will remain available, but the review of accumulated vulnerability reports will begin only after August 3.
Sursa: opennet.ro
