Stay updated with the latest in technology, global innovations, and key economic trends. From AI breakthroughs to global energy market insights, we bring you the news that matters.
Daniel Stenberg Fights Off Flawed CVE Request on Curl.
Get link
Facebook
X
Pinterest
Email
Other Apps
-
Curl Creator Daniel Stenberg Details Ongoing Battles Against 'CVE Hunters' Targeting Open-Source Projects
Daniel Stenberg, the founder and lead maintainer of the ubiquitous open-source tool Curl, has publicly highlighted a persistent headache plagueing open-source maintainers: security researchers relentlessly pushing for CVE (Common Vulnerabilities and Exposures) designations on trivial software bugs.
Since becoming an official CVE Numbering Authority (CNA), Curl has maintained direct control over assigning security vulnerability tracking numbers for its codebase rather than relying on central triage organizations like MITRE. While Curl has legitimately issued 57 CVEs under this program, a recent dispute underscored the growing tension between maintainers and researchers seeking security accolades for non-issues.
The Dispute: Wildcard Certificates and Leading Dots
The controversy stems from a minor parsing bug in Curl regarding TLS/SSL wildcard certificate validation.
Specifically, if a user attempts a connection using a domain name configured with a leading dot (such as .nnewstech.com), Curl accepted a wildcard certificate issued for *.nnewstech.com. The reporter insisted this behavior constituted a serious security vulnerability due to improper certificate validation.
Stenberg and the Curl security team rejected the CVE request, classifying the issue as a harmless operational bug rather than a security exploit. Their rationale centered on practical exploitability:
Invalid DNS Syntax: Domain names starting with a leading dot cannot be resolved over standard Domain Name System (DNS) protocols.
Implausible Threat Vector: The scenario can only trigger if a victim manually edits their local system /etc/hosts file to assign an invalid leading-dot domain and explicitly directs it to a malicious server holding the wildcard certificate.
Because the real-world security risk was "lower than low," Curl refused to issue a CVE. Undeterred, the reporter appealed Curl's decision to MITRE multiple times in an attempt to override the maintainers. Following review, MITRE formally upheld Curl's decision, ruling that the bug did not constitute a security vulnerability.
The wider phenomenon of "CVE farming" or "CVE junk" has led many cybersecurity students, automated scanners, and bug-hunting enthusiasts to attempt to bolster their resumes or bug-hunting portfolios by requesting official CVE numbers. This encourages reporters to exaggerate the severity of minor bugs that occur in exceptional cases, placing a massive administrative burden on open-source maintainers who spend hours without compensation reviewing, debating, and rejecting absurd security report submissions.
Before Curl became a CNA, security researchers could easily bypass open-source maintainers by submitting reports directly through third-party intermediaries, resulting in the inappropriate assignment of CVEs to software without the consent of the core developers. By holding its own CNA status, Curl has established stricter criteria for what constitutes a genuine threat, protecting enterprise end users from false security alarms.
A genuine security vulnerability requires a workable threat model in which attackers can remotely compromise data integrity, confidentiality, or availability without requiring the victim to make unusual or non-standard system configuration changes. By adhering to realistic attack conditions, Stenberg helps establish a better industry standard for how open-source projects screen security reports.
Ask me anything about this article. No data is stored for your question.
Curl Creator Daniel Stenberg Details Ongoing Battles Against 'CVE Hunters' Targeting Open-Source Projects
Daniel Stenberg, the founder and lead maintainer of the ubiquitous open-source tool Curl, has publicly highlighted a persistent headache plagueing open-source maintainers: security researchers relentlessly pushing for CVE (Common Vulnerabilities and Exposures) designations on trivial software bugs.
Since becoming an official CVE Numbering Authority (CNA), Curl has maintained direct control over assigning security vulnerability tracking numbers for its codebase rather than relying on central triage organizations like MITRE. While Curl has legitimately issued 57 CVEs under this program, a recent dispute underscored the growing tension between maintainers and researchers seeking security accolades for non-issues.
The Dispute: Wildcard Certificates and Leading Dots
The controversy stems from a minor parsing bug in Curl regarding TLS/SSL wildcard certificate validation.
Specifically, if a user attempts a connection using a domain name configured with a leading dot (such as .nnewstech.com), Curl accepted a wildcard certificate issued for *.nnewstech.com. The reporter insisted this behavior constituted a serious security vulnerability due to improper certificate validation.
Stenberg and the Curl security team rejected the CVE request, classifying the issue as a harmless operational bug rather than a security exploit. Their rationale centered on practical exploitability:
Invalid DNS Syntax: Domain names starting with a leading dot cannot be resolved over standard Domain Name System (DNS) protocols.
Implausible Threat Vector: The scenario can only trigger if a victim manually edits their local system /etc/hosts file to assign an invalid leading-dot domain and explicitly directs it to a malicious server holding the wildcard certificate.
Because the real-world security risk was "lower than low," Curl refused to issue a CVE. Undeterred, the reporter appealed Curl's decision to MITRE multiple times in an attempt to override the maintainers. Following review, MITRE formally upheld Curl's decision, ruling that the bug did not constitute a security vulnerability.
The wider phenomenon of "CVE farming" or "CVE junk" has led many cybersecurity students, automated scanners, and bug-hunting enthusiasts to attempt to bolster their resumes or bug-hunting portfolios by requesting official CVE numbers. This encourages reporters to exaggerate the severity of minor bugs that occur in exceptional cases, placing a massive administrative burden on open-source maintainers who spend hours without compensation reviewing, debating, and rejecting absurd security report submissions.
Before Curl became a CNA, security researchers could easily bypass open-source maintainers by submitting reports directly through third-party intermediaries, resulting in the inappropriate assignment of CVEs to software without the consent of the core developers. By holding its own CNA status, Curl has established stricter criteria for what constitutes a genuine threat, protecting enterprise end users from false security alarms.
A genuine security vulnerability requires a workable threat model in which attackers can remotely compromise data integrity, confidentiality, or availability without requiring the victim to make unusual or non-standard system configuration changes. By adhering to realistic attack conditions, Stenberg helps establish a better industry standard for how open-source projects screen security reports.
US Federal Trade Commission Prepares Lawsuit Against YouTube Over Content Moderation Transparency The U.S. Federal Trade Commission (FTC) is preparing to file a consumer protection lawsuit against YouTube , following a multi-year regulatory investigation into the platform's content moderation practices, according to a report by Bloomberg News . The FTC investigation centers on whether YouTube's parent company, Alphabet , misled users by shadowbanning, demonetizing, or removing content despite explicit platform terms promising tolerance for diverse viewpoints. Led by FTC Chairman Andrew Ferguson , Bureau of Consumer Protection Director Chris Mufarreh , and agency attorneys, the probe focuses on whether arbitrary account suspensions and content takedowns constitute deceptive trade practices under federal consumer protection laws. Despite the momentum toward formal litigation, internal debate remains within the agency: Internal Dissension: Some career staff members have privately...
Tencent Hy Research Team Debuts Hy4 Preview: Flagship 770B-A49B Architecture Built for High-Density Agentic Workflows The Tencent Hy research team has officially released the preview version of its next-generation foundation model, Hy4 . Markedly shifting strategy from the smaller, budget-focused design of its predecessor, Hy3, Tencent’s new release enters the frontier class delivering benchmark performance on par with leading Chinese AI flagships including DeepSeek V4 Pro , Kimi K3 , GLM-5.3 , and Qwen3.8 Max . Built on a massive 770B-A49B Mixture-of-Experts (MoE) architecture , Hy4 dramatically expands parameter capacity while incorporating a native 1-Million Token Context Window . This extended memory capacity allows the model to maintain context across long-horizon reasoning tasks and handle complex multi-step technical execution without losing track of instructions. Despite the significant increase in parameter scale, Tencent has maintained a strong price-to-performance advantage...
OpenAI to Terminate AI Model Partnership with Cursor Following SpaceX’s $60 Billion Acquisition OpenAI has officially announced plans to terminate its AI model supply agreement with popular AI-assisted coding platform Cursor , setting a firm cutoff deadline for late night on November 12, 2026 . This strategic separation follows SpaceX’s all-stock acquisition of Anysphere the parent company behind Cursor in a deal valued at $60 billion in June. The contract termination marks another major escalation in the high-profile feud between OpenAI CEO Sam Altman and SpaceX founder Elon Musk. Contract Breach Concerns & Corporate Disputes OpenAI cited change-of-control provisions built into its original service contract, asserting that it could not adequately verify whether SpaceX would comply with its standard terms of service. The AI lab pointed to past contractual disputes involving entities under Musk’s leadership as rationale for exercising its termination right following the chang...
Apple Announces September 9 Event 'Surprise and Shine' Featuring New CEO John Ternus and iPhone Ultra Debut Apple has officially sent out invitations for its annual flagship product launch event, scheduled for September 9, 2026, at 10:00 AM Pacific Time . The event features the tagline " Surprise and shine " accompanied by key art depicting the iconic Apple logo illuminated by a dramatic solar backdrop. This event marks a historic turning point for Apple as it will be the first major keynote delivered by John Ternus in his new role as Chief Executive Officer. Ternus officially succeeds Tim Cook, who steps down on September 1, exactly one week prior to the presentation. Industry expectations for the hardware and software announcements include: Next-Gen iPhones: Official debuts for the flagship iPhone 18 Pro and iPhone 18 Pro Max . The standard iPhone 18 is reportedly postponed until next year to make room for Apple’s long-anticipated foldable device, tentatively du...
Xbox Introduces Disc-to-Digital Conversion: Transfer Physical Game Discs to Digital Licenses Microsoft has officially launched its long-rumored Disc-to-Digital conversion program for Xbox, allowing physical media owners to convert their physical disc collection into full digital game licenses . To initiate the conversion, users simply insert a supported physical disc into an Xbox One or Xbox Series X console, launch the game, and claim digital ownership through the system menu. Once converted, the license functions identically to a standard digital purchase unlocking full support for Xbox Play Anywhere cross-platform PC play and cloud streaming via Xbox Cloud Gaming . Crucially, claiming a digital license does not invalidate or destroy the physical disc itself, which remains fully functional for standard offline playback. To prevent duplicate usage across accounts, Microsoft leverages unique disc-embedded hardware IDs baked into Xbox One and Xbox Series X optical media: Account Ow...
President Trump Signs Executive Order Establishing the U.S. Space Academy Under NASA U.S. President Donald Trump has officially signed an executive order directing the creation of the U.S. Space Academy , a specialized national educational institution designed along the lines of traditional military academies such as the United States Military Academy at West Point but operating entirely under NASA rather than the Department of Defense. According to the official announcement, the academy will offer a comprehensive curriculum covering operational astronautics, aerospace engineering, and specialized civilian space operations. The initiative aims to build a dedicated talent pipeline to support the continued expansion of the U.S. Space Force as well as the rapidly growing commercial space sector. NASA Administrator Jared Isaacman has been appointed to chair a specialized advisory panel tasked with outlining the academy's operational structure. The panel has been given 120 days to s...
Anthropic Enhances Claude Cowork Desktop with Built-in Browser for Isolated Web Automation Anthropic has officially updated the desktop version of Claude Cowork , introducing an embedded, native web browser directly within the desktop application. This integration allows Claude Cowork to execute web-browsing tasks natively without relying on external web browsers or secondary browser extensions. Previously, Claude Cowork relied on the Claude for Chrome browser extension to navigate web pages. However, that approach introduced functional limitations and privacy concerns. Granting an AI assistant access to a user's primary daily browser exposed personal browsing histories, stored cookies, and active session data when the AI simply required a basic web-rendering environment to fetch information. To address this, Anthropic embedded a dedicated browser framework directly into the desktop client. Anthropic clearly delineated the security model: "This is Claude's browser, not yo...
Comments
Post a Comment