Conversation

Today we celebrate the five year anniversary of 's bug-bounty. It has resulted in 69 reported vulnerabilities and almost 80,000 USD payouts. Out of a total of 439 submissions. 86 of them were considered "informative", which mostly means they were handled as normal bugs.

Submit your suspected curl securirty issue here: https://hackerone.com/curl

2
0
0

bonus graph: fixed/introduced vulnerabilities in over time:

1
2
0
@bagder
All in the red since 2014, too bad...
0
0
1

@worr I don't think anything in particular changed, maybe that we slowly got more eyes involved in the looking for issues

0
0
0

@bagder Thanks for sharing these numbers!

I'm curious, is it possible to also get a breakdown by severity for the reported ones?

1
0
0

@tarakiyee I have this graph that sort of shows it a little

0
0
0