[Daniel's week] August 14, 2026

Daniel Stenberg daniel at haxx.se
Fri Aug 14 23:46:11 CEST 2026


Hello!

Happy to report that another work week has ended.

## security

No new vulnerabilities confirmed this week. Part of the week was spent working 
on addressing the third one we have in the queue, reported last Friday. The 
report frequency continues to be rather low and we are happy.

Today however we got confirmation that the era of AI slop submissions is not 
entirely passed as we received a case where the security researcher seems to 
have been grossly misled by his AI[1]. Banned now.

## performance

I spent a large portion of this week writing up a performance test system for 
curl. It was about time and it starts to look decent now [2].

## backports are coming

A new customer requested backported vulnerability fixes for a few older curl 
versions, and once we have agreed to the finer details in my plan work on this 
will commence. Official curl patch releases will happen, starting in a few 
weeks. These releases will be done under the rock-solid [3]  label and will 
not become publicly available. This is hard work so we really need 
compensation to make this possible. If you too are interested in getting older 
security-patched curl releases, get in touch.

The original releases, all the code on GitHub and all coming curl releases are 
of course still available for free and at no charge as usual.

## Windows

Early this week I was complaining on Mastodon [6] about the fact that 
receiving information about Windows related problems for curl is problematic 
as nobody in the curl security uses or runs Windows. This was picked up by 
heise.de [5] and I even received a few emails from people offering to help 
out, but it is not an easy task. This is what I responded to one of the 
persons:

Hi!

Thanks for offering to help out and contribute to the curl project.We do have 
a lack of Windows contributors and developers so all additional help is 
appreciated!

curl is an Open Source project. No one pays for the Windows version so there 
is no short-term monetary gain here, and we are not in a position where we are 
able to pay anyone for this help. Yes, Microsoft has been shipping curl as 
part of Windows since several years back and yes there are many commercial 
applications on Windows that use curl or libcurl, but (with the exception of a 
single sponsor) none of them pays anything for that.

The way to help out in the curl project, be it with Windows specific things or 
with anything else, is to join the conversation and speak up when you have 
something to add or assist with. Don’t wait for an invitation. Show up. Pick 
up something that needs work and go.

My guess is that in order to actually get to a position where you are able to 
help us in a meaningful way, you need to get familiar with the project: with 
our ways of working, with our CI setup, how you build curl, how we 
communicate, the basic architecture and layout of the source code but also to 
have a decent knowledge and awareness of the specific network protocols that 
are involved in the area of the code where you think you might want to poke. 
But that’s just me. You decide for yourself how you want to go about it.

There is no “accepting” or “letting you in” to becoming a curl contributor. 
You’re already welcome and you can join and participate at your own will 
whenever you want at the level you yourself decide. Everyone can do this and 
everyone is welcome to join, to participate, to help, to answer questions, to 
offer pull-requests, to help debug issues, etc.

For Windows related issues and pull-requests, we try to mark them with the 
Windows tag. Feel free to dig around them to see where we currently could use 
assistance.

We also have this starter point on how to get started helping out in the curl 
project: https://curl.se/docs/help-us.html

Welcome!

## LG unit

I got a brand new contribution to the screenshotted curl credits collection 
[4] this week: an LG air-condition controller. Judging by the version number 
shown, it is probably decently old. If you check the collection, the new entry 
is all the way at the bottom of the page.

## Coming up

- curl 8.22.0-rc2 ships Monday
- get started on backports
- keep polishing the performance test setup and website

## Links

[1] = https://hackerone.com/reports/3938185
[2] = https://daniel.haxx.se/blog/2026/08/14/curl-performance-2/
[3] = https://rock-solid.curl.dev/
[4] = https://daniel.haxx.se/blog/2016/10/03/screenshotted-curl-credits/
[5] = https://www.heise.de/en/news/curl-Nobody-wants-to-work-with-Windows-11409147.html
[6] = https://mastodon.social/@bagder/117061983160992793

-- 

  / daniel.haxx.se


More information about the daniel mailing list