a CVE dispute
Summary
The article discusses curl’s role as a CNA, the process and costs of issuing CVEs for security issues, and a specific dispute with MITRE over whether a reported issue deserved a CVE. It also explains a technical case involving a leading-dot hostname and wildcard certificates, which was eventually deemed not a security vulnerability. The post emphasizes responsible disclosure and the open-source CVE process.