Daniel Stenberg recounts curl's first CVE dispute since the project became a CNA (CVE Numbering Authority). A reporter submitted a bug involving wildcard certificate matching when a hostname has a leading dot — an illegal DNS name requiring a local attacker and a very specific chain of conditions to exploit. The curl team fixed the bug but declined to assign a CVE, classifying it as 'lower than LOW' severity. The reporter escalated to MITRE, which contacted the curl team three times over several months. On June 24, MITRE's TL-Root sided with curl, confirming no CVE would be assigned. The post also explains the real-world cost of CVEs given libcurl's ~30 billion installs, and why the team takes care not to trigger unnecessary security churn across the ecosystem.