curl-curl/docs/BUG-BOUNTY.md
Daniel Stenberg ca7ef4b817
BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026
Remove mentions of the bounty and hackerone.

Closes #20312
2026-01-26 08:26:28 +01:00

569 B

The curl bug bounty

Up until the end of January 2026 there was a curl bug bounty. It is no more.

The curl project does not offer any rewards for reported bugs or vulnerabilities. We also do not aid security researchers to get such rewards for curl problems from other sources either.

A bug bounty gives people too strong incentives to find and make up "problems" in bad faith that cause overload and abuse.

We still appreciate and value valid vulnerability reports.