Monitoring
Reporting series · Quarterly · 104 observations
curl vulnerability disclosures
Quarterly curl vulnerability disclosures, with severity and finder-credit attribution.
45 disclosures in 2026 through 2 September 2026
Descriptive- Total
- 45
- AI-linked
- 22
- 2025
- 9
- 2014–2023 mean
- 13.1
Quarterly disclosures
2026 severity and credit text
- Low
- 30
- Medium+
- 15
- Explicit AI
- 2
- AI affiliation
- 20
- AI-linked total
- 22
Provenance files
215 records · data through 2026-09-02
Fixed-codebase series
| Series | 2025 | 2026 | AI-linked | Through |
|---|---|---|---|---|
| curl disclosures | 9 | 45 | 22 | 2 September 2026 |
| OpenSSL disclosures | 6 | 49 | 27 | 25 August 2026 |
Series definition
- Measure
- One vulnerability record published in curl's public machine-readable vulnerability ledger, counted in the quarter of its public publication date.
- Counting
- Fetch curl's public JSON record, keep one row per dated vulnerability entry, aggregate by publication quarter, and preserve missing quarters as explicit zero observations.
- Date
- Use the public `published` date in curl's vulnerability record. The final quarter ends at the latest source date and is marked incomplete rather than extended to the nominal quarter end.
- Denominator
- All curl vulnerability disclosures in the quarter. No denominator for research effort, submissions, compute, or search time is available.
- AI-linked credit
- A deterministic finder-credit text classification with separate explicit AI, AI-affiliation-only, fuzzing, and other bands. The central observation numerator combines the first two for backward-compatible sensitivity analysis; it remains noisy attribution evidence, not proof of method use.
- Frequency
- Quarterly
Data and sources
Fetch curl's public JSON, preserve a canonical raw snapshot, derive a per-record audit table, fill zero quarters, rebuild the compact central observations, and validate severity plus attribution summaries.
- curl vulnerability data · Primary Data
- METR — LLMs' Contribution to Discoveries · External Reference
Analysis and limits
Analysis
A negative-binomial or Poisson count model with calendar time, a post-2025 level and slope term, quarter effects, and an exposure offset for incomplete periods. Model choice follows dispersion diagnostics.
- Compare 2025 and partial 2026 with several pre-period windows
- Exclude the incomplete final quarter
- Use annual counts to reduce release-batching sensitivity
- Separate explicit AI markers, AI-affiliation-only credits, and total disclosures
- Estimate Low and Medium-or-higher disclosure rates separately
- Estimate curl and OpenSSL jointly with project-specific levels and trends
Limits
- Disclosure volume depends on search effort, incentives, triage, reporting rules, and release timing.
- A finder credit can omit AI use or name an AI organization even when a model did not produce the finding.
- More disclosures, especially low-severity findings, need not imply more important security progress.
- The latest quarter is incomplete through 2026-09-02.
- One software project is a pipeline sentinel and reporting control, not a representative measure of science.
Recent data
| Quarter | Total | AI-linked | Coverage |
|---|---|---|---|
| 2024-Q4 | 2 | 0 | Complete |
| 2025-Q1 | 3 | 0 | Complete |
| 2025-Q2 | 3 | 0 | Complete |
| 2025-Q3 | 2 | 1 | Complete |
| 2025-Q4 | 1 | 1 | Complete |
| 2026-Q1 | 10 | 3 | Complete |
| 2026-Q2 | 26 | 12 | Complete |
| 2026-Q3 | 9 | 7 | Through 2 September 2026 |