Updated bug bounty stats, six years in:

520 reports
78 confirmed security vulnerabilities
104 "informative" reports, bugs that weren't vulnerabilities
11 marked as "AI slop"

The rest were just different kinds of not applicable. Some more crazy than others.

The latest confirmed curl vulnerability (CVE-2025-0725) was reported 90 days ago.

There is currently zero issues in our queue.

curl.se/docs/bugbounty.html

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/bagder/statuses/114389539878135652 on your instance and quote it. (Note that quoting is not supported in Mastodon.)