OCaml maintainer sees traversal probes ten minutes after opening a fix PR, and rclone logs 40 disclosures in a month
Anil Madhavapeddy, a Cambridge CS professor and OCaml compiler maintainer, released a cohttp 6.3.0 path-traversal fix and found percent-encoded traversal probes hitting his live webserver about ten minutes after opening the public PR; he reproduced the exploit locally with his own agent in under a minute after Claude Fable refused the task and DeepSeek V4 Pro complied. In the Hacker News discussion on 2026-08-28, rclone maintainer Nick Craig-Wood reported over 40 security disclosures in the last month against roughly 20 in the project's first ten years, with about 75% containing something real, and GitHub CVE assignment slipping from 2-3 days to 3-4 weeks so releases now ship marked CVE-PENDING. His argument is that embargo-based open source security process no longer buys any time.
↳ Follow the thread