<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening.]]></title><description><![CDATA[<p>First of all, *most* of FOSS security reports nowadays (that I see in <a href="https://chaos.social/tags/curl" rel="tag">#<span>curl</span></a> and <a href="https://chaos.social/tags/apache" rel="tag">#<span>apache</span></a> httpd) are non-threatening.</p><p>They are edge cases under highly constructed preconditions. Yes, not impossible, but unlikely to be ever encountered.</p><p>Before LLMs, no researcher would have invested the time to explore those scenarios. my guess.</p><p>Yes, we fix them. But, they could also have been a bug report.<img src="https://forum.other.li/assets/plugins/nodebb-plugin-emoji/emoji/android/1f481.png?v=9aba40efd77" class="not-responsive emoji emoji-android emoji--information_desk_person" style="height:23px;width:auto;vertical-align:middle" title="💁" alt="💁" /><img src="https://forum.other.li/assets/plugins/nodebb-plugin-emoji/emoji/android/1f3fb.png?v=9aba40efd77" class="not-responsive emoji emoji-android emoji--skin-tone-2" style="height:23px;width:auto;vertical-align:middle" title="🏻" alt="🏻" />‍<img src="https://forum.other.li/assets/plugins/nodebb-plugin-emoji/emoji/android/2642.png?v=9aba40efd77" class="not-responsive emoji emoji-android emoji--male_sign" style="height:23px;width:auto;vertical-align:middle" title="♂" alt="♂" />️</p>]]></description><link>https://forum.other.li/topic/6cf1a83e-1037-48ec-aa67-2113eb052828/first-of-all-most-of-foss-security-reports-nowadays-that-i-see-in-curl-and-apache-httpd-are-non-threatening.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 05 Jun 2026 04:24:59 GMT</lastBuildDate><atom:link href="https://forum.other.li/topic/6cf1a83e-1037-48ec-aa67-2113eb052828.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 15 May 2026 06:10:10 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening. on Fri, 15 May 2026 11:39:37 GMT]]></title><description><![CDATA[<p><span><a href="https://chaos.social/@icing">@<span>icing</span></a></span> I like to think we're closing the back doors and zero days nation state actors had found and not reported.</p>]]></description><link>https://forum.other.li/post/https://mastodon.social/ap/users/116266959024807499/statuses/116578397568845160</link><guid isPermaLink="true">https://forum.other.li/post/https://mastodon.social/ap/users/116266959024807499/statuses/116578397568845160</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 15 May 2026 11:39:37 GMT</pubDate></item><item><title><![CDATA[Reply to First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening. on Fri, 15 May 2026 10:25:31 GMT]]></title><description><![CDATA[<p><span><a href="https://chaos.social/@icing">@<span>icing</span></a></span> And then people observe the changes required to fix the problem and can use them to create their exploit right away, even before the fix is released.</p>]]></description><link>https://forum.other.li/post/https://genealysis.social/users/Flominator/statuses/116578106198284494</link><guid isPermaLink="true">https://forum.other.li/post/https://genealysis.social/users/Flominator/statuses/116578106198284494</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 15 May 2026 10:25:31 GMT</pubDate></item><item><title><![CDATA[Reply to First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening. on Fri, 15 May 2026 09:46:49 GMT]]></title><description><![CDATA[<p><span><a href="https://hachyderm.io/@stevel" rel="nofollow noopener">@<span>stevel</span></a></span> <span><a href="https://chaos.social/@icing" rel="nofollow noopener">@<span>icing</span></a></span> There's more than RCE, e.g. heartbleed had a 8.6 cvss w/o RCE, but had aggravating factors that aren't evaluated by the CVSS scale, like how widespread the vulnerable configuration is.</p><p><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N" rel="nofollow noopener"><span>https://www.</span><span>first.org/cvss/calculator/3.1#</span><span>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N</span></a></p><p>In comparison, we have a 4-bytes uninitialized stack value leak in application logs bug to be reported soon.  CVSS 3.1 Low<br /><a href="https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N" rel="nofollow noopener"><span>https://www.</span><span>first.org/cvss/calculator/3.1#</span><span>CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N</span></a></p>]]></description><link>https://forum.other.li/post/https://infosec.exchange/users/aris/statuses/116577954033613881</link><guid isPermaLink="true">https://forum.other.li/post/https://infosec.exchange/users/aris/statuses/116577954033613881</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 15 May 2026 09:46:49 GMT</pubDate></item><item><title><![CDATA[Reply to First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening. on Fri, 15 May 2026 09:37:37 GMT]]></title><description><![CDATA[<p><span><a href="https://infosec.exchange/@aris">@<span>aris</span></a></span> <span><a href="https://chaos.social/@icing">@<span>icing</span></a></span> if its not RCE in a normal deployment - it's just a normal bug. Makes sense,</p>]]></description><link>https://forum.other.li/post/https://hachyderm.io/users/stevel/statuses/116577917809779949</link><guid isPermaLink="true">https://forum.other.li/post/https://hachyderm.io/users/stevel/statuses/116577917809779949</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 15 May 2026 09:37:37 GMT</pubDate></item><item><title><![CDATA[Reply to First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening. on Fri, 15 May 2026 08:52:09 GMT]]></title><description><![CDATA[<p><span><a href="https://chaos.social/@icing" rel="nofollow noopener">@<span>icing</span></a></span> at libssh we're considering the policy of filing all bugs under a certain CVSS threshold (5 or 6) as regular bug reports in bug tracking and fix them without any embargo to avoid clogging up the security pipeline</p>]]></description><link>https://forum.other.li/post/https://infosec.exchange/users/aris/statuses/116577739056100692</link><guid isPermaLink="true">https://forum.other.li/post/https://infosec.exchange/users/aris/statuses/116577739056100692</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 15 May 2026 08:52:09 GMT</pubDate></item><item><title><![CDATA[Reply to First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening. on Fri, 15 May 2026 08:49:34 GMT]]></title><description><![CDATA[<p><span><a href="https://mastodon.art/@holsta">@<span>holsta</span></a></span> Ah yes. Sorry. I saw two separate posts drifting onto my timeline (which isn't normally about curl or security stuff). They seemed related in an interesting way which I thought I would comment on it. But maybe I should've noticed they're both from people who are well aware of eachother.</p>]]></description><link>https://forum.other.li/post/https://en.osm.town/users/harry_wood/statuses/116577728856914667</link><guid isPermaLink="true">https://forum.other.li/post/https://en.osm.town/users/harry_wood/statuses/116577728856914667</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 15 May 2026 08:49:34 GMT</pubDate></item><item><title><![CDATA[Reply to First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening. on Fri, 15 May 2026 08:43:07 GMT]]></title><description><![CDATA[<p><span><a href="https://chaos.social/@icing" rel="nofollow noopener">@<span>icing</span></a></span> I suspect the Linux kernel is an exception.</p>]]></description><link>https://forum.other.li/post/https://infosec.exchange/users/alwayscurious/statuses/116577703501762967</link><guid isPermaLink="true">https://forum.other.li/post/https://infosec.exchange/users/alwayscurious/statuses/116577703501762967</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 15 May 2026 08:43:07 GMT</pubDate></item><item><title><![CDATA[Reply to First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening. on Fri, 15 May 2026 08:41:18 GMT]]></title><description><![CDATA[<p><span><a href="https://en.osm.town/@harry_wood">@<span>harry_wood</span></a></span> What? Stefan is literally on the curl team.</p><p>Why are you like this?</p>]]></description><link>https://forum.other.li/post/https://mastodon.art/users/holsta/statuses/116577696398036494</link><guid isPermaLink="true">https://forum.other.li/post/https://mastodon.art/users/holsta/statuses/116577696398036494</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 15 May 2026 08:41:18 GMT</pubDate></item><item><title><![CDATA[Reply to First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening. on Fri, 15 May 2026 08:11:33 GMT]]></title><description><![CDATA[<p><span><a href="https://mas.to/@swelljoe" rel="nofollow noopener">@<span>swelljoe</span></a></span> <span><a href="https://chaos.social/@icing" rel="nofollow noopener">@<span>icing</span></a></span> eh… either way, it used to be every time a new developer looked at a corner of a code base that hasn't been touched in 10, 20, 30 years we get, at the very least a bug fix a refactoring</p><p>and at least one new person who's now familiar with that code… <img src="https://forum.other.li/assets/plugins/nodebb-plugin-emoji/emoji/android/2b05.png?v=9aba40efd77" class="not-responsive emoji emoji-android emoji--arrow_left" style="height:23px;width:auto;vertical-align:middle" title="⬅" alt="⬅" />️ and the loss of this is perhaps the most frustrating part</p>]]></description><link>https://forum.other.li/post/https://cathode.church/users/meena/statuses/116577579403244642</link><guid isPermaLink="true">https://forum.other.li/post/https://cathode.church/users/meena/statuses/116577579403244642</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 15 May 2026 08:11:33 GMT</pubDate></item><item><title><![CDATA[Reply to First of all, *most* of FOSS security reports nowadays (that I see in #curl and #apache httpd) are non-threatening. on Fri, 15 May 2026 06:38:01 GMT]]></title><description><![CDATA[<p><span><a href="https://chaos.social/@icing">@<span>icing</span></a></span> after twenty or thirty years, the really scary stuff has probably already been found in anything popular. (Probably.)</p>]]></description><link>https://forum.other.li/post/https://mas.to/users/swelljoe/statuses/116577211635745828</link><guid isPermaLink="true">https://forum.other.li/post/https://mas.to/users/swelljoe/statuses/116577211635745828</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Fri, 15 May 2026 06:38:01 GMT</pubDate></item></channel></rss>