No, that is the point, they are not going to accept your vuln report. They are taking a holiday.
But the message is pretty clear: if you’re not a paid customer, you are not getting patches or support from upstream during this month.
Plan accordingly.
Curl is also something that should be thoroughly sandboxed to begin with, because even if there are no vulnerabilities in curl itself, its a tool for downloading arbitrary data over the internet, and you may well accidentally trigger vulnerabilities in every other part of your environment just by downloading arbitrary data to your shell...