One Maintainer Rewrote an Auth Library Twice Because No One Would Merge the Security Patch

Jul 17, 2026 By Sara Park

In the summer of 2024, a security researcher discovered a critical vulnerability in a widely used authentication library. He wrote a patch, submitted it, and waited. Eighteen months later, the patch still hadn't been merged. So he rewrote the entire library from scratch. Then he rewrote it again. This is the story of how open source's bus factor and funding crisis turn security patches into year-long ordeals — and why the industry's dependence on unpaid labor is a ticking time bomb.

The Patch That Sat for 18 Months

The maintainer, who asked to remain anonymous for fear of retaliation, first noticed the flaw while auditing dependencies for a client project. The library was used by thousands of applications, including several Fortune 500 companies. The vulnerability allowed an attacker to bypass token validation under specific conditions — a classic authentication bypass that could lead to account takeover.

He submitted a detailed pull request with a fix, test cases, and a description of the exploit path. The repository had three named maintainers, but only one was actively reviewing pull requests. That maintainer was overwhelmed, responding to dozens of issues per week while holding a full-time job. The PR sat for three months with no comment.

After six months, the researcher pinged the thread. No response. He tried emailing the maintainers directly. One auto-replied that he had taken a break from open source. The other two never replied. By month twelve, the vulnerability had been discussed on a security mailing list, and the researcher knew attackers were aware of it.

He made a decision: he would fork the library, apply his patch, and maintain the fork himself. But the fork lacked the ecosystem trust of the original. Integrations, documentation, and CI tooling all assumed the canonical repository. So he began work on a complete rewrite — a cleaner, more auditable codebase that could be proposed as a replacement. The rewrite took nearly a year of nights and weekends.

Why Good Patches Go Unmerged

The story is not unique. A three-year-old fix went unmerged while a zero-day exploited the same flaw in another project. The common thread is the bus factor: when a project relies on one or two unpaid volunteers, any interruption — a job change, a family emergency, burnout — stalls progress. The patch isn't rejected; it's simply never seen.

Review bottlenecks compound the problem. A maintainer might have the best intentions but only two hours per week for open source. Security patches compete with feature requests, documentation updates, and routine maintenance. Features often win because they feel more rewarding. Security work is invisible when it succeeds, visible only when it fails.

There is also a false sense of safety — what some call the ELIZA effect applied to code. Just as early chatbot users attributed understanding to ELIZA, project users assume that because a library is popular, it must be secure. The reality is that popularity attracts no more review than obscurity. A 2024 study of npm packages found that median review time for security patches was over 200 days, and 15% of patches were never merged.

The priority mismatch is structural. Corporate users of open source rarely fund maintenance. They consume the library, report bugs, and sometimes contribute code — but the boring work of auditing dependencies and fixing security holes falls to volunteers. The result is a system that looks functional but is riddled with unpatched flaws.

The Cost of Rewriting Twice

The first rewrite took roughly 400 hours. The maintainer restructured the library to reduce complexity, added comprehensive test coverage, and documented every authentication flow. He submitted it as a replacement for the original, hoping the community would adopt it. The response was lukewarm. Some users worried about breaking changes; others didn't see the point. The original maintainer never replied.

But the fork had its own problems. The maintainer had designed the API to be cleaner, but that meant existing integrations needed updates. Few projects migrated. The vulnerability remained exploitable in the original library. So he started a second rewrite — this time intentionally backward-compatible, a drop-in replacement that fixed the flaw without changing any public interfaces. That took another 300 hours.

The second rewrite was more successful. Several downstream projects adopted it. But the maintainer was exhausted. He had spent over 700 unpaid hours — roughly the equivalent of four months of full-time work — on a project that had given him nothing but stress. The original library still had thousands of users running the vulnerable version.

The community trust eroded further when it emerged that the vulnerability had been exploited in at least two known incidents. One involved a startup that lost customer data; another targeted a government agency. Both could have been prevented if the patch had been merged promptly. The maintainer now says he would think twice before reporting a vulnerability again.

To put 700 hours in perspective: a typical security engineer at a large tech company might bill around US$150–250 per hour. That means the maintainer effectively donated between US$105,000 and US$175,000 of labor to fix a problem that should have been resolved with a single code review. The asymmetry is not just financial — it is a failure of the entire ecosystem to value security work.

Zoox Recall Parallels

In July 2026, Amazon's Zoox issued a software recall after a robotaxi became confused by heavy smoke from a nearby fire. The vehicle stopped in the middle of a road, blocking emergency vehicles. The National Highway Traffic Safety Administration (NHTSA) had warned AV companies about such edge cases, but the fix came only after an incident. The recall mirrors the auth library story: an edge case known to insiders, ignored until it caused harm.

Both cases involve systems that are safety-critical — one for physical safety, one for digital security. In both, the people who understood the risk lacked the authority or resources to fix it. In the auth library, the maintainer wasn't a project lead. In Zoox, the engineers who flagged the smoke issue may have been overruled by product timelines.

The regulatory pressure on AV companies creates a compliance-driven approach to safety: fix what regulators notice. Open source has no equivalent regulator. There is no NHTSA for npm or PyPI. The closest thing is the Open Source Security Foundation (OpenSSF), but it has no enforcement power. Vulnerabilities remain unpatched until a CVE is published — and even then, adoption of patches is slow.

First responder safety lessons from the Zoox recall apply to digital infrastructure too. When an auth library fails, the "first responders" are security teams who must scramble to mitigate an active breach. They need patches to be available and easy to deploy. A patch that sits unmerged is like a fire extinguisher locked in a closet with no key.

Some argue that comparing a robotaxi recall to an open source patch is an overreach. After all, the Zoox recall involved physical harm, while a software bug might only cause data loss. But the line is blurring. As authentication libraries gate access to critical infrastructure — power grids, healthcare systems, financial networks — a bypass can lead to real-world damage. The 2021 Colonial Pipeline ransomware attack started with a compromised VPN password. An unpatched auth library could enable similar attacks at scale.

LLM Jailbreaks and Auth Libraries

The same month as the Zoox recall, researcher Dave Kuszmar published findings on systemic LLM jailbreak vulnerabilities. He discovered that flaws in authentication and authorization libraries enabled prompt injection attacks across multiple major models. The exploits worked because the libraries did not properly validate context boundaries — the same class of bug as the auth bypass that sat unmerged for 18 months.

Kuszmar's work revealed an industry-wide security problem: foundational components — auth libraries, token handlers, input sanitizers — are built on the same fragile volunteer labor. When a vulnerability is found in one, it often echoes across dozens of projects. An unpatched auth library can become a vector for jailbreaking an LLM that uses it for API authentication.

The dark side of unpatched dependencies is that attackers chain them. A bug in a JWT library might seem minor until combined with a misconfigured reverse proxy. The maintainer's two rewrites were an attempt to break that chain, but without adoption, the chain remains. The industry's security posture depends on the weakest link, and the weakest links are often the most popular, least maintained libraries.

This is not a problem that can be solved by more audits or better tooling alone. Tooling can find vulnerabilities, but it cannot force maintainers to merge patches. It cannot pay for the time required to review, test, and deploy a fix. The human bottleneck remains the hardest to address.

Consider a counter-argument: some maintainers deliberately delay merging patches to avoid destabilizing their projects. They may be waiting for more testing or a coordinated release. But in this case, 18 months of silence is not deliberation — it is neglect. The patch itself was well-tested and included in the fork. The delay was not a quality decision; it was a failure of triage.

Who Pays for Open Source Security?

In the same week that the auth library story unfolded, a $400 million deal was announced: GPU financiers turning to inference chips, funding AI infrastructure at scale. Meanwhile, the maintainer who rewrote the library twice had no funding at all. He had applied for a grant from a foundation but was rejected because his project did not meet "critical infrastructure" criteria — even though it was used by critical infrastructure.

The funding gap in open source security is staggering. A 2025 survey by the Linux Foundation found that 60% of maintainers of critical projects receive no compensation. The median annual funding for a security-critical project is under $2,000. Compare that to the $400 million chip-backed loan, or the billions spent on AI model training. The asymmetry is grotesque.

Some companies have started corporate sponsorship programs, but they are often performative. A $10,000 donation to a project used by millions is a rounding error in a cloud budget. The maintainer of the auth library received a total of $500 in donations over two years. He spent that on CI credits. The rest came out of his savings.

Sustainability requires structural change. Grants from foundations like OpenSSF or the Sovereign Tech Fund help, but they are limited and competitive. Corporate users need to internalize the cost of the dependencies they rely on. Some proposals suggest a "security tax" on commercial use of open source, similar to copyright levies. Others argue for more maintainer-friendly licensing that requires paid contributions. No model has gained consensus.

A more optimistic view is that the tide is turning. The European Union's Cyber Resilience Act, expected to take effect around 2027, will impose security requirements on software sold in the EU, including open source components. That could force companies to fund maintenance or risk liability. But legislation moves slowly, and the patch sat unmerged for 18 months — a lifetime in software security.

Practical Takeaways for 2026

First, patch fast. Supply-chain hygiene starts with accepting that every dependency is a potential liability. Organizations should monitor their dependencies for unmerged security patches and be willing to fork if necessary. The cost of maintaining a fork is lower than the cost of a breach.

Second, reduce the bus factor. Projects should aim for at least three active maintainers with merge rights. If you rely on a library with a single maintainer, consider contributing time — not just code, but review and triage. Shared ownership spreads the load and prevents the kind of bottleneck that stalled the auth library patch.

Third, treat authentication libraries like any critical safety system. They deserve the same rigor as aircraft software or medical devices. That means formal verification, regular audits, and a clear incident response plan. The industry should establish a vulnerability disclosure standard for open source with guaranteed response times.

Finally, support maintainers with time, money, and tooling. If your company uses a library, donate to its maintainer or fund a part-time role. Tools like automated dependency updates and fuzzing can help, but they cannot replace human judgment. A security audit on two build pipelines found one dependency repeated in both — a reminder that duplication hides risk. Pay for the audits. Pay for the patches. The alternative is a system where the people who keep the internet running are burning out, one unmerged pull request at a time.

One concrete step is to adopt a "dependency pledge": for every library your organization depends on, assign a team member to monitor its issue tracker and pull requests. If a critical patch goes unmerged for more than 30 days, escalate to a fork or sponsor a maintainer. This is not charity — it is self-defense. The maintainer who rewrote the library twice did so because no one else would. Next time, it could be your library, your patch, your 700 hours.

Recommend Posts
Tech

One Audit Log's Retention Period Cost a Six-Figure Insurance Claim Payout

By Yusuke Tanaka/Jul 17, 2026

A six-figure insurance claim was denied because audit logs had been overwritten. This article examines how retention policies, log integrity gaps, and supply-chain blind spots turn security practices into financial liabilities.
Tech

One Team Measured React Server Components Against a Raw DOM Write and Found Nothing Broke

By Lucas Mendes/Jul 17, 2026

A production team compared React Server Components against a raw DOM baseline. Two weeks, 1.2 million sessions, and no regressions. Here's what they learned.
Tech

SwiftUI and Kotlin Multiplatform Both Pass Mobile Interviews but Hire Different Engineers

By Lucas Mendes/Jul 17, 2026

SwiftUI and Kotlin Multiplatform both clear mobile interviews in 2026, but they attract distinct engineer profiles. This feature explores trade-offs, job market signals, and how to pick your lane.
Tech

One Maintainer's Unmerged Pull Request Exposed a CI Token Leak That Was Active for Eight Months

By Deepa Iyer/Jul 17, 2026

A lone maintainer's CI debugging session uncovered a token exposed in plaintext for eight months. The unmerged PR reveals systemic gaps in supply-chain security.
Tech

One Paid License Consultant Wrote a Copyleft Exception That Stalled Three Acquisitions

By Sara Park/Jul 17, 2026

A single copyleft exception drafted by a freelance consultant stalled three acquisitions, costing tens of millions. How one bad clause became a poison pill.
Tech

One Platform Team's iOS Push Certificate Expiration Cost Three App Releases

By Lucas Mendes/Jul 17, 2026

A platform team missed a push notification certificate expiry, delaying three app releases by 6-8 weeks. This analysis covers the hidden dependencies in mobile CI/CD and how to automate certificate lifecycle management.
Tech

Flutter's Widget Tree vs SwiftUI's View Body Two Teams Paid for Both

By Deepa Iyer/Jul 17, 2026

A business breakdown of Flutter and SwiftUI: what each gets right, the hidden costs, and why teams often end up maintaining both stacks.
Tech

A Security Audit on Two Build Pipelines Found One Dependency Repeats in Both

By Deepa Iyer/Jul 17, 2026

A security audit of two competing CI/CD pipelines revealed a shared vulnerable dependency. This article examines the economic and technical blind spots that allow such duplication, and offers practical fixes for engineering leaders.
Tech

One Maintainers Three-Year-Old Fix Went Unmerged While a Zero-Day Exploited the Same Flaw

By Deepa Iyer/Jul 17, 2026

A three-year-old pull request fixing a null-pointer dereference sat unmerged while attackers exploited the same flaw. This feature examines why good fixes rot in open source and how to prevent it.
Tech

One Training Budget Split Inference Between NVIDIA and AMD and Cut Costs by a Third

By Sara Park/Jul 17, 2026

Splitting inference across NVIDIA and AMD GPUs can cut costs by a third. A deep dive into real-world economics, vendor negotiation, and the tradeoffs of a mixed fleet.
Tech

React Server Components and HTMX Both Offer Less JS But One Team Quit

By Lucas Mendes/Jul 17, 2026

A mid-sized SaaS team adopted both React Server Components and HTMX to reduce JavaScript. Half the engineers quit within six months. Here is what each technology gets right and wrong, and the human cost of choosing wrong.
Tech

Two Package Registries Priced the Same Dependency at a Five-Fold Security Audit Gap

By Sara Park/Jul 17, 2026

A single dependency costs five times more to audit on one registry than another. This article breaks down the economics of security in package registries.
Tech

One Maintainer Rewrote an Auth Library Twice Because No One Would Merge the Security Patch

By Sara Park/Jul 17, 2026

A maintainer rewrote an auth library twice after a critical security patch sat unmerged for 18 months. The story exposes the human cost of open source maintenance, supply-chain risk, and the funding gap in critical infrastructure.
Tech

SwiftUI and Jetpack Compose Share One Syntax But Two Team Cultures

By Deepa Iyer/Jul 17, 2026

SwiftUI and Jetpack Compose look alike on the surface, but beneath the syntax lie two radically different team cultures—Apple's playground mentality versus Google's engineering sandbox.
Tech

One Engineer's Config Drift Brought Down a Monorepo CI Pipeline for Two Months

By Deepa Iyer/Jul 17, 2026

A single mismerged YAML file silently corrupted a monorepo CI pipeline for 67 days. This is the story of how config drift escapes detection and what teams can learn from it.
Tech

One Maintainer Cut a Single Monorepo Tool That Replaced Three Dedicated CI Systems

By Yusuke Tanaka/Jul 17, 2026

How a single engineer replaced three separate CI systems with one monorepo tool, cutting pipeline runtime by 70% and monthly costs by 60%.
Tech

One Unpaywalled Dependency Tree Forced a Maintainer to Refactor Ten Years of Patches

By Deepa Iyer/Jul 17, 2026

A maintainer spent 300–400 hours untangling a decade of patches after an unpaywalled dependency tree collapsed. The story reveals systemic risks in open-source dependency chains and the unpaid labor behind critical infrastructure.
Tech

One Abandoned Android Library Cost Each Fork Four Months of Maintenance

By Yusuke Tanaka/Jul 17, 2026

When an Android library drops maintenance, forking it costs teams roughly four months each. This article examines the hidden costs, business models, and practical steps to reduce the burden.
Tech

One Inference Engineer's GPU Swarm Saved a Week per Pipeline Run

By Deepa Iyer/Jul 17, 2026

How a mid-size AI lab cut fine-tuning time from 7 days to 14 hours by swapping a homogeneous A100 cluster for a dynamic swarm of heterogeneous GPUs on spot instances.
Tech

One Maintainers License Change Forced Forty Downstream Projects to Adopt an Alternative Fork

By Yusuke Tanaka/Jul 17, 2026

When Redis Labs added the Commons Clause in 2018, over 40 downstream projects were forced to evaluate alternatives. KeyDB emerged as a viable fork, revealing lessons in open-source governance and license stability.