Signed: Former workaholic.
> Probably not. But we will.
A pleasant dose of humanity in decidedly inhuman times.
I wonder what is there to work on curl 50 hour weeks for 7 years?
This is Exceptional. Perfect EuroMaxxing
If you get sick during vacation, you get those vacation days "refunded" back. If you suddenly are called in to work, somehow, during vacation, that time cannot be vacation time.
You can't (generally) be fired without a notice period, resulting in job security to such a degree that ~6k in an emergency fund is plenty to be VERY secure, as you also get unemployment support otherwise anyway. Does this result in incompetent people not getting fired? No. You still fire them, you just have to deal with them another month after that. It's not a big price to pay.
How is this all possible? Who subsidizes it? We all simply pay some % of our income to support this system. That's it. A couple percent, a couple bucks, and we get to basically never worry about starving or becoming homeless.
You can have this, too, if you vote and protest and use democracy to make life better, not worse, for everyone.
I thought this was due to AI slop spam before I read the blog entry.
They aren't. If you ignore vulnerability report from an entity without a support contract, the vulnerability doesn't disappear just because the entities with support contracts are not aware of it
* curl is mature enough that the chance of an impactful bug is basically zero * if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co * if there is such a bug, it's more important that it gets patched in package managers and rolled out. Upstream releases can wait.
I can see something like nginx being in that spot but curl is primarily user initiated and pointed at a known target rather than internet facing accepting connections
Wonder if this means just publishing vulnerablities without contact with curl team would be responsible (you have no other path to tell vulnerable users)
(See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven...)
No, that is the point, they are not going to accept your vuln report. They are taking a holiday.
Also, what's an example of this rent seeking in open source you're talking about?
The responsible thing would have been to simply wait another month, considering you've been warned about the delay.
Curl is also something that should be thoroughly sandboxed to begin with, because even if there are no vulnerabilities in curl itself, its a tool for downloading arbitrary data over the internet, and you may well accidentally trigger vulnerabilities in every other part of your environment just by downloading arbitrary data to your shell...
Naturally some people find that this offensive since this puts a price to that “bliss”.
IMO Writing correct software the first time around - so formal methods.
But the tooling isn't there yet (though lightweight versions, e.g. strong type systems like rust's, are and significantly reduce the security issue load).
And if you find something halfway through the month then oh no two weeks to reply, that's basically a standard business interaction at that point.
Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.There's no such thing as "responsible disclosure on a technicality". Don't be a dick, and work in good faith to keep users safe.
I'm not sure it's be reasonable to leave an actively exploited critical bug until August. Nor would I be too interested in playing middle man or paying for support from curl to get it out.
Of course, "European companies normally ignore their paid customers too from May to August" is factious, but there is a slight hint of truth in there, in that things generally is slower, at least in the South/West countries I'm more familiar with.
2 weeks is the acceptable limit in the UK for example (where also has 20-35 holiday is common) though if you can convince your boss otherwise, you can take longer, but most people can't
But the message is pretty clear: if you’re not a paid customer, you are not getting patches or support from upstream during this month.
Plan accordingly.
Is this at the executive level?
many engineers actually work that way, right? We are employed for 12 months and give our availability fully to the company and we get salary for it, why isn't it allowed to others?
Pipe it to bash? game over
Pipe it to less/more? Better hope your distro keeps those patched
Open the file in a browser or PDF reader? Hey, look at all this shiny new attack surface!
This can be an unwelcome feature for some people, for example, if you want to have a vacation in the northern hemisphere summer season instead and/or maybe you don't have substantial family in Australia (or at least, those you actually want to see).
The auscorp reddit has a yearly thread on this issue: https://www.reddit.com/r/auscorp/comments/1mw6pqt/end_of_yea...
Those with school aged children might also want to save some of their annual for the mid-term/mid-year breaks as well. (Our academic years are aligned to calendar years)

The curl project will not accept or otherwise handle any vulnerability reports during the month of July 2026. We call it the curl summer of bliss.
curl’s submission form on Hackerone will be paused starting July 1, 2026.

Summer of bliss starts: July 1, 2026. 00:00 CEST
Submissions resume: August 3 2026. 09:00 CEST
The security email address will also be a dead end, as we will not process or otherwise care about security or vulnerability reports sent to us that way either.
Whatever issue you find that you feel a need to report to the curl project during this month has to wait. curl’s Hackerone form opens for submissions again on Monday August 3.
We do not accept vulnerability reports over email in general, and this fact remains during and after our vacation.

The curl maintainers will use this time of less pressure to take in some extra air and to enjoy the summer. Maybe stroll outside a bit more. Breath. Some of us may spend some of this time to see other places.
We may get some extra time to spend on fixing bugs or working on new code. Fun stuff!
As a direct side-effect of this summer of bliss, to allow us some more time to handle the issues that might have piled up for us in early August, we also push the release date of 8.22.0 two weeks into the future. Now scheduled to happen on September 2, 2026.
As previously mentioned, we have been under a huge pressure for the last four months or so. Now we need some rest. We do not expect this deluge to be over.
curl’s issue and pull-request trackers on GitHub remain open and active like normal.
If you and your Open Source projects also want to participate in the summer of bliss 2026: just do it and let us know! I would of course encourage you to do so. To take care of yourself as a top priority.
Probably not. But we will.
Then we get to read about it in August. Or you get a support contract and we get to read about it earlier.
Everyone with a paid support contracts will of course still get full and appropriate service even during this period.

Daniel, in a relaxed state.
The ice cream image was made by fotografierende from Pixabay
On hacker news.
I've "retired" into agriculture and a lot of farmers take a month off after harvest time to go fishing or other wise relax (this generally means filling up a couple of deep chest freezers with fish for the rest of the year).
Look at how any "FOSS + VC + for-profit" company in the last 5-10 years worked out, and you'll see the playbook.
Greed, sometimes. Gotta get those usercounts high to get acquihired / to sell out / to flip on the paid subs for formerly free features.
I can’t remember the word for “prosocial through lowering cost to zero” is but sometimes that too.
Since then a diff of the two projects will be a perfect list of security issues and will make designing an attack rather easy...
Yeah me neither.
I think the only thing that would convince people to move away from curl at this point would be if curl had a heartbleed level vulnerability and failed to fix it quickly.
Now I personally wish lawyers and plumbers also got into the free work thing but here we are
That is not ignoring but announcing a delay.
Bigger companies may have only limited number of people checking the mailboxes in july and august, that doesn't excuse not sending a small reply announcing delays but I guess they take it so much for granted they don't realize other continents aren't used to those kinds of delays. However in May and June every company is totally operational ( that doesn't mean nobody take holidays ). If you request something to one named person, that sole person can have scheduled holidays, parental or medical leave any time of the year. If it is a team mailbox, you should get an answer.
Wiktionary:
Benevolent, altruistic, unselfish, beneficent, philanthropic, selfless
Wise customers know this.
Digital assets or work are a bit different in that making a second copy is trivial. It’d be different if every computer in the world were bespoke and needed its own bespoke software. So that makes OSS a viable option for those who can but we also can’t expect everyone to default OSS. We can default to asking that the service and prices be reasonable though.
I think maybe with the American PoV of "the customer is always right", that might basically feel like a slap and the face and being ignored. Of course, we should understand that every human needs to rest during the year, but if you don't have that opportunity yourself by law, maybe you're less knowing about that being a thing in other more modern countries?
Lawyers start out as humans but something about going into law school and then private practice, and feeding them after midnight turns them into... something else entirely.
Every once in a while there is an exception. Then that guy says "If your sending me to Australia I'm going to use my vacation to scuba drive the Great Barrier Reef" - and his body is never found. True story, it took months for someone else to figure out everything that guy knew.
So every single business, everywhere in American, has at least two full-time employees or at least one other backup that is available when you want to vacation and the stores/businesses never close? I'm guessing the ones that don't have that (if they exists), just never have vacation, or how does that work? Sounds like a fever-dream, but I guess if that's what your experience tells you.
Stores remain open because they ensure somebody isn't on vacation and thus able to work. They sometimes give extra pay if you work a holiday (this is rare though - generally there is somebody who wants the hours/pay more than this holiday off - they can take time off a different day).
For small business (think a plumber) it is common to arrange a competitor who will take care of your emergency customers needs.