cd /news/ai-safety/libexpat-will-not-accept-vulnerabili… · home topics ai-safety article
[ARTICLE · art-28131] src=github.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Libexpat will not accept vulnerability reports before 2026-08-01

The libexpat project announced it will not accept or handle any new vulnerability reports until 2026-08-01, following a similar break by the cURL project. Maintainers urge security researchers and AI/fuzzing tools to pause reporting until that date to allow sustainable work on known issues and the upcoming release.

read1 min publishedJun 15, 2026
[Notifications](/login?return_to=%2Flibexpat%2Flibexpat)You must be signed in to change notification settings -
[Fork 516](/login?return_to=%2Flibexpat%2Flibexpat)

Description #

Hello! 👋

Following a recent announcement of the cURL project, the libexpat project is joining in with a break and will not accept or otherwise handle any new vulnerability reports until 2026-08-01 starting today, take a deep breath, and continue working on

[known unfixed vulnerabilities](https://github.com/libexpat/libexpat/issues/1160)and

[the upcoming release](https://github.com/libexpat/libexpat/issues/1276)at a sustainable pace.

That means:

If you run into vulnerabilities in libexpat and would like to disclose them responsibly, please hold your horses until 2026-08-01 and thenreach out with a report. -

If you are throwing AI or fuzzing or security research at libexpat these days please hit the button and resume on/after 2026-08-01. #

If you would like to fund work on libexpat, please reach out via e-mail. #

If you would like to be notified of the break period ending early, please feel free to subscribe to this issue. Thanks for your understanding! 🙏

Sebastian Pipping, Berlin, 2026-06-15 PS: Comments are intentionally closed, please reach out via the e-mail in my profile, instead.

CC @Smattr @berkayurun @hannob @StanFromIreland @netliomax25-code @alessandrogario

Metadata #

Metadata #

Assignees

Labels

Type

Fields

Give feedback

── more in #ai-safety 4 stories · sorted by recency
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/libexpat-will-not-ac…] indexed:0 read:1min 2026-06-15 ·