[Daniel's week] August 14, 2026
Daniel Stenberg
daniel at haxx.se
Fri Aug 14 23:46:11 CEST 2026
Hello!
Happy to report that another work week has ended.
## security
No new vulnerabilities confirmed this week. Part of the week was spent working
on addressing the third one we have in the queue, reported last Friday. The
report frequency continues to be rather low and we are happy.
Today however we got confirmation that the era of AI slop submissions is not
entirely passed as we received a case where the security researcher seems to
have been grossly misled by his AI[1]. Banned now.
## performance
I spent a large portion of this week writing up a performance test system for
curl. It was about time and it starts to look decent now [2].
## backports are coming
A new customer requested backported vulnerability fixes for a few older curl
versions, and once we have agreed to the finer details in my plan work on this
will commence. Official curl patch releases will happen, starting in a few
weeks. These releases will be done under the rock-solid [3] label and will
not become publicly available. This is hard work so we really need
compensation to make this possible. If you too are interested in getting older
security-patched curl releases, get in touch.
The original releases, all the code on GitHub and all coming curl releases are
of course still available for free and at no charge as usual.
## Windows
Early this week I was complaining on Mastodon [6] about the fact that
receiving information about Windows related problems for curl is problematic
as nobody in the curl security uses or runs Windows. This was picked up by
heise.de [5] and I even received a few emails from people offering to help
out, but it is not an easy task. This is what I responded to one of the
persons:
Hi!
Thanks for offering to help out and contribute to the curl project.We do have
a lack of Windows contributors and developers so all additional help is
appreciated!
curl is an Open Source project. No one pays for the Windows version so there
is no short-term monetary gain here, and we are not in a position where we are
able to pay anyone for this help. Yes, Microsoft has been shipping curl as
part of Windows since several years back and yes there are many commercial
applications on Windows that use curl or libcurl, but (with the exception of a
single sponsor) none of them pays anything for that.
The way to help out in the curl project, be it with Windows specific things or
with anything else, is to join the conversation and speak up when you have
something to add or assist with. Don’t wait for an invitation. Show up. Pick
up something that needs work and go.
My guess is that in order to actually get to a position where you are able to
help us in a meaningful way, you need to get familiar with the project: with
our ways of working, with our CI setup, how you build curl, how we
communicate, the basic architecture and layout of the source code but also to
have a decent knowledge and awareness of the specific network protocols that
are involved in the area of the code where you think you might want to poke.
But that’s just me. You decide for yourself how you want to go about it.
There is no “accepting” or “letting you in” to becoming a curl contributor.
You’re already welcome and you can join and participate at your own will
whenever you want at the level you yourself decide. Everyone can do this and
everyone is welcome to join, to participate, to help, to answer questions, to
offer pull-requests, to help debug issues, etc.
For Windows related issues and pull-requests, we try to mark them with the
Windows tag. Feel free to dig around them to see where we currently could use
assistance.
We also have this starter point on how to get started helping out in the curl
project: https://curl.se/docs/help-us.html
Welcome!
## LG unit
I got a brand new contribution to the screenshotted curl credits collection
[4] this week: an LG air-condition controller. Judging by the version number
shown, it is probably decently old. If you check the collection, the new entry
is all the way at the bottom of the page.
## Coming up
- curl 8.22.0-rc2 ships Monday
- get started on backports
- keep polishing the performance test setup and website
## Links
[1] = https://hackerone.com/reports/3938185
[2] = https://daniel.haxx.se/blog/2026/08/14/curl-performance-2/
[3] = https://rock-solid.curl.dev/
[4] = https://daniel.haxx.se/blog/2016/10/03/screenshotted-curl-credits/
[5] = https://www.heise.de/en/news/curl-Nobody-wants-to-work-with-Windows-11409147.html
[6] = https://mastodon.social/@bagder/117061983160992793
--
/ daniel.haxx.se
More information about the daniel
mailing list