Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Important heads-up to FOSS maintainers by Daniel from curl:

Important heads-up to FOSS maintainers by Daniel from curl:

Scheduled Pinned Locked Moved Uncategorized
7 Posts 7 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • mechko@chaos.socialM This user is from outside of this forum
    mechko@chaos.socialM This user is from outside of this forum
    mechko@chaos.social
    wrote last edited by
    #1

    Important heads-up to FOSS maintainers by Daniel from curl:

    "Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools."

    Since I'm working for Alpha-Omega currently, please reach out to me if you could use some support regarding this. We're setting up various programs to help FOSS maintainers in the times of "high-quality chaos".

    https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/

    js@ap.nil.imJ ringods@hachyderm.ioR sjaveed@mastodon.socialS eliotlear@mastodon.socialE gnirre@mastodon.socialG 5 Replies Last reply
    3
    0
    • R relay@relay.infosec.exchange shared this topic
    • mechko@chaos.socialM mechko@chaos.social

      Important heads-up to FOSS maintainers by Daniel from curl:

      "Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools."

      Since I'm working for Alpha-Omega currently, please reach out to me if you could use some support regarding this. We're setting up various programs to help FOSS maintainers in the times of "high-quality chaos".

      https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/

      js@ap.nil.imJ This user is from outside of this forum
      js@ap.nil.imJ This user is from outside of this forum
      js@ap.nil.im
      wrote last edited by
      #2

      @mechko Is any open source project in scope? If I maintain an open source project, can I just ask you to run it against my project?

      1 Reply Last reply
      0
      • mechko@chaos.socialM mechko@chaos.social

        Important heads-up to FOSS maintainers by Daniel from curl:

        "Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools."

        Since I'm working for Alpha-Omega currently, please reach out to me if you could use some support regarding this. We're setting up various programs to help FOSS maintainers in the times of "high-quality chaos".

        https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/

        ringods@hachyderm.ioR This user is from outside of this forum
        ringods@hachyderm.ioR This user is from outside of this forum
        ringods@hachyderm.io
        wrote last edited by
        #3

        @mechko
        @purpleidea FYI 👆🏼

        1 Reply Last reply
        0
        • R relay@relay.publicsquare.global shared this topic
        • mechko@chaos.socialM mechko@chaos.social

          Important heads-up to FOSS maintainers by Daniel from curl:

          "Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools."

          Since I'm working for Alpha-Omega currently, please reach out to me if you could use some support regarding this. We're setting up various programs to help FOSS maintainers in the times of "high-quality chaos".

          https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/

          sjaveed@mastodon.socialS This user is from outside of this forum
          sjaveed@mastodon.socialS This user is from outside of this forum
          sjaveed@mastodon.social
          wrote last edited by
          #4

          @mechko in other words, the cURL codebase is, with apologies to Douglas Adams, “Mostly Bugless”?

          1 Reply Last reply
          0
          • mechko@chaos.socialM mechko@chaos.social

            Important heads-up to FOSS maintainers by Daniel from curl:

            "Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools."

            Since I'm working for Alpha-Omega currently, please reach out to me if you could use some support regarding this. We're setting up various programs to help FOSS maintainers in the times of "high-quality chaos".

            https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/

            eliotlear@mastodon.socialE This user is from outside of this forum
            eliotlear@mastodon.socialE This user is from outside of this forum
            eliotlear@mastodon.social
            wrote last edited by
            #5

            @mechko The only thing that's surprising is that it found only one vulnerability. Curl is a monster of a package with huge numbers of dependencies.

            janvenetor@mastodontti.fiJ 1 Reply Last reply
            0
            • eliotlear@mastodon.socialE eliotlear@mastodon.social

              @mechko The only thing that's surprising is that it found only one vulnerability. Curl is a monster of a package with huge numbers of dependencies.

              janvenetor@mastodontti.fiJ This user is from outside of this forum
              janvenetor@mastodontti.fiJ This user is from outside of this forum
              janvenetor@mastodontti.fi
              wrote last edited by
              #6

              @eliotlear @mechko and another good point, the tooling doesn't find new classes of exploits or new approaches to break code.

              Lots of old and familiar kind of holes to go through, still..

              1 Reply Last reply
              0
              • mechko@chaos.socialM mechko@chaos.social

                Important heads-up to FOSS maintainers by Daniel from curl:

                "Any project that has not scanned their source code with AI powered tooling will likely find huge number of flaws, bugs and possible vulnerabilities with this new generation of tools."

                Since I'm working for Alpha-Omega currently, please reach out to me if you could use some support regarding this. We're setting up various programs to help FOSS maintainers in the times of "high-quality chaos".

                https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/

                gnirre@mastodon.socialG This user is from outside of this forum
                gnirre@mastodon.socialG This user is from outside of this forum
                gnirre@mastodon.social
                wrote last edited by
                #7

                @mechko Do you know why it took so long for curl to get access to Mythos? Is there a long line of projects waiting...?

                1 Reply Last reply
                0
                • pixelate@tweesecake.socialP pixelate@tweesecake.social shared this topic
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups