Curl Ends Bug Bounty Program Due to AI-Generated Low-Quality Reports
Summary
Hide ▲
Show ▼
The curl project is ending its HackerOne bug bounty program by the end of January 2026 due to an overwhelming number of low-quality, AI-generated vulnerability reports. The project will no longer offer rewards for reported bugs and will shift to an internal submission process via GitHub. The decision was made to reduce the strain on the curl security team and to discourage low-effort submissions. Daniel Stenberg, the founder and lead developer of curl, cited a significant increase in invalid reports, many of which appear to be AI-generated, as the primary reason for this change.
Timeline
-
22.01.2026 21:01 1 articles · 23h ago
Curl Ends Bug Bounty Program Due to AI-Generated Reports
The curl project will end its HackerOne bug bounty program on January 31, 2026, due to an overwhelming number of low-quality, AI-generated vulnerability reports. The project will shift to an internal submission process via GitHub starting February 1, 2026. Daniel Stenberg, the founder and lead developer, cited the strain on the security team and the need to reduce noise as the primary reasons for this change.
Show sources
- Curl ending bug bounty program after flood of AI slop reports — www.bleepingcomputer.com — 22.01.2026 21:01
Information Snippets
-
Curl's bug bounty program will end on January 31, 2026.
First reported: 22.01.2026 21:011 source, 1 articleShow sources
- Curl ending bug bounty program after flood of AI slop reports — www.bleepingcomputer.com — 22.01.2026 21:01
-
The project will no longer offer rewards for reported bugs or assist researchers in obtaining compensation from third parties.
First reported: 22.01.2026 21:011 source, 1 articleShow sources
- Curl ending bug bounty program after flood of AI slop reports — www.bleepingcomputer.com — 22.01.2026 21:01
-
The curl security team has been overwhelmed by low-effort, AI-generated vulnerability reports.
First reported: 22.01.2026 21:011 source, 1 articleShow sources
- Curl ending bug bounty program after flood of AI slop reports — www.bleepingcomputer.com — 22.01.2026 21:01
-
Starting February 1, 2026, security issues must be reported directly through GitHub.
First reported: 22.01.2026 21:011 source, 1 articleShow sources
- Curl ending bug bounty program after flood of AI slop reports — www.bleepingcomputer.com — 22.01.2026 21:01
-
Daniel Stenberg has shared examples of AI-generated 'slop' reports and noted a steep rise in submissions compared to other open-source projects.
First reported: 22.01.2026 21:011 source, 1 articleShow sources
- Curl ending bug bounty program after flood of AI slop reports — www.bleepingcomputer.com — 22.01.2026 21:01