Curl will end its bug bounty program by the end of January due to excessive AI generated reports ~comp security.cyber open source Link 63 votes
CVE-2020-19909 is everything that is wrong with CVEs (false bug report for curl) ~comp security.cyber Article 1001 words, published Aug 25 2023 25 votes
The lead developer of curl analyzed its known security vulnerabilities and determined that half of them are related to it being written in C ~comp programming languages programming security.cyber Article 1528 words 12 votes