{"id":48354,"date":"2025-07-04T16:55:51","date_gmt":"2025-07-04T20:55:51","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=48354"},"modified":"2025-07-05T00:36:07","modified_gmt":"2025-07-05T04:36:07","slug":"common-vulnerabilities-and-exposures-cve-funding","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2025\/07\/04\/common-vulnerabilities-and-exposures-cve-funding\/","title":{"rendered":"Common Vulnerabilities and Exposures (CVE) Funding"},"content":{"rendered":"<p><a href=\"https:\/\/www.csoonline.com\/article\/3963190\/cve-program-faces-swift-end-after-dhs-fails-to-renew-contract-leaving-security-flaw-tracking-in-limbo.html\">Cynthia Brumfield<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=43700607\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.csoonline.com\/article\/3963190\/cve-program-faces-swift-end-after-dhs-fails-to-renew-contract-leaving-security-flaw-tracking-in-limbo.html\">\n<p>After DHS did not renew its funding contract for reasons unspecified, MITRE&rsquo;s 25-year-old Common Vulnerabilities and Exposures (CVE) program was slated for an abrupt shutdown on April 16, which would have left security flaw tracking in limbo.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/gavinhoward.com\/2025\/04\/replacing-cve\/\">Gavin D. Howard<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=43708409\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/gavinhoward.com\/2025\/04\/replacing-cve\/\"><p>The CVE system has been less good about securing our infrastructure than they\nhave been about giving headaches to some of the most important projects. <a href=\"https:\/\/daniel.haxx.se\/blog\/2023\/08\/26\/cve-2020-19909-is-everything-that-is-wrong-with-cves\/\">Curl\ngets bogus CVEs<\/a> all the time and <a href=\"https:\/\/daniel.haxx.se\/blog\/2023\/09\/05\/bogus-cve-follow-ups\/\">has to spend precious time dealing with\nthem<\/a>. <a href=\"https:\/\/www.postgresql.org\/about\/news\/cve-2020-21469-is-not-a-security-vulnerability-2701\/\">Postgresql does too<\/a>. The Linux kernel went a different route and\njust <a href=\"https:\/\/www.youtube.com\/watch?v=Rg_VPMT0XXw\">spams CVEs<\/a> so that kernel CVEs essentially become worthless.<\/p><p>Worthless? Does that mean that CVEs were actually worth something to people?<\/p><p>Yes, absolutely. Script-kiddies that consider themselves &ldquo;security researchers&rdquo;\ntry to find bugs in big projects and then get them labeled as CVEs so they can\n<a href=\"https:\/\/lwn.net\/Articles\/944209\/\">add those CVEs to their r&eacute;sum&eacute;s<\/a>. As <a href=\"https:\/\/news.ycombinator.com\/item?id=37608432\">one user on Hacker News said<\/a>,\n&ldquo;Unfortunately, the CVE database(s) are too noisy to be useful.&rdquo;<\/p><p>In fact, it got so bad that Curl decided to do <em>extra work<\/em> to <a href=\"https:\/\/daniel.haxx.se\/blog\/2024\/01\/16\/curl-is-a-cna\/\">become a\nCNA<\/a>, just so they can reject spurious reports and avoid the <a href=\"https:\/\/nvd.nist.gov\/\">NVD<\/a> from\ngiving excessively high vulnerability scores.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.thecvefoundation.org\/newsroom\/posts\/2025-04-16-launch\">CVE Foundation<\/a> (via <a href=\"https:\/\/news.ycombinator.com\/item?id=43704430\">Hacker News<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.thecvefoundation.org\/newsroom\/posts\/2025-04-16-launch\">\n<p>The CVE Foundation has been formally established to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program, a critical pillar of the global cybersecurity infrastructure for 25 years.<\/p>\n<\/blockquote>\n\n<p><a href=\"https:\/\/www.theregister.com\/2025\/04\/18\/splintering_cve_bug_tracking\/\">Jessica Lyons<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.theregister.com\/2025\/04\/18\/splintering_cve_bug_tracking\/\">\n<p>Earlier this week, the widely used Common Vulnerabilities and Exposures (<a href=\"https:\/\/www.cve.org\/\">CVE<\/a>) program faced doom as the US government <a href=\"https:\/\/www.theregister.com\/2025\/04\/16\/homeland_security_funding_for_cve\/\">discontinued<\/a> funding for MITRE, the non-profit that operates the program. Uncle Sam U-turned at the <a href=\"https:\/\/www.theregister.com\/2025\/04\/16\/cve_program_funding_save\/\">very last minute<\/a>, and promised another 11 months of cash [via CISA] to keep the program going.<\/p><p>Meanwhile, the EU is rolling its own.<\/p><p>The European Union Agency for Cybersecurity (ENISA) developed and maintains this alternative, which is known as the <a href=\"https:\/\/euvd.enisa.europa.eu\/\">EUVD<\/a>, or the European Union Vulnerability Database.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/05\/08\/curl-takes-action-against-ai-bug-reports\/\">curl Takes Action Against AI Bug Reports<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Cynthia Brumfield (via Hacker News): After DHS did not renew its funding contract for reasons unspecified, MITRE&rsquo;s 25-year-old Common Vulnerabilities and Exposures (CVE) program was slated for an abrupt shutdown on April 16, which would have left security flaw tracking in limbo. Gavin D. Howard (via Hacker News): The CVE system has been less good [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2025-07-04T20:55:54Z","apple_news_api_id":"aee12dda-e899-4986-af07-9f876c693410","apple_news_api_modified_at":"2025-07-04T20:55:54Z","apple_news_api_revision":"AAAAAAAAAAD\/\/\/\/\/\/\/\/\/\/w==","apple_news_api_share_url":"https:\/\/apple.news\/AruEt2uiZSYavB5-HbGk0EA","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[1506,2698,1927,31,448,30,991,48,96],"class_list":["post-48354","post","type-post","status-publish","format-standard","hentry","category-technology","tag-curl","tag-cybersecurity-and-infrastructure-security-agency-cisa","tag-european-union","tag-ios","tag-linux","tag-mac","tag-open-source-software","tag-security","tag-web"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/48354","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=48354"}],"version-history":[{"count":1,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/48354\/revisions"}],"predecessor-version":[{"id":48355,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/48354\/revisions\/48355"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=48354"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=48354"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=48354"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}