In March 2026, Daniel Stenberg announced that curl would not accept vulnerability reports in July. No security patches. No disclosure coordination. No inbox triage. Four weeks of auto-replies saying "we'll get back to you in August." He called it the Summer of Bliss.
The reaction was mostly supportive. About time, people said. Maintainers deserve rest. Burnout is real. All of that is true. But underneath the support was something closer to dread. Not for Daniel, who had earned a break after 20,463 commits over 25 years. The dread was for everyone else.
The internet runs on curl. Every smartphone has it. Every cloud provider uses it. Every CI pipeline calls it. It transfers data between millions of machines every second. And for one month, the person most qualified to respond if something goes catastrophically wrong has said he won't be available. Not because he's sick or overworked or underpaid. Because he scheduled a vacation and told everyone about it in advance.
This is the part that should scare you more than any zero-day. We have built the most sophisticated information processing infrastructure in human history on a model where one person's decision to take a month off constitutes a systemic risk. And we have no mechanism, no plan, no institutional backup for the scenario that person decides not to come back.
The ratios tell the story bluntly. Daniel Stenberg has 20,463 commits to curl. The next most active contributor has 3,747. The distribution is not a bell curve. It is a spike followed by a long tail. This is not unique to curl. It is how almost all critical open source infrastructure is structured. One or two people carry the cognitive load, and everyone else is somewhere between periodic contributor and drive-by patch. The bus factor is not a theoretical risk. It is a statistical description of how almost everything you depend on is maintained.
Every company running curl has been operating under an implicit contract. The terms were never agreed to, never signed, never even stated aloud. The contract said: Daniel Stenberg will fix your vulnerabilities, respond to your bug reports, review your pull requests, and maintain compatibility with your systems. He will do this for free, on his own time, for as long as you need him to. In exchange, you will not pay him, you will not staff an alternative, and you will treat his work as a reliable utility indistinguishable from running water or electrical power.
Daniel just sent a notice of contract termination. Not legally, of course. But structurally. He said "I will not do this work for one month" and the entire dependency chain had no response other than "okay, we'll wait." No company could escalate. No SLA could be invoked. No manager could be called. The most critical security channel in the curl ecosystem is a single person who decided to stop answering email for four weeks.
The asymmetry here is precise. Daniel can take July off because he has nothing to lose. No stock grants tied to uptime. No liability for unpatched CVEs. No SLA with financial penalties. The companies depending on curl cannot take July off because they have everything to lose. The maintainer has all the freedom and the user has all the risk. This imbalance has always existed. It just was never this visible before.
Consider what happens if a critical curl vulnerability is discovered on July 15. A remote code execution in the TLS handshake, say, or a buffer overflow in HTTP/2 frame parsing. In normal times, there is a well-practiced disclosure process. The reporter emails the curl security list. Daniel triages, reproduces, writes a patch, coordinates with distros, ships a release within days. In July, there is no one to email. The auto-reply says the report will b