NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation’s cybersecurity infrastructure. There is a growing backlog of vulnerabilities submitted to the NVD and requiring analysis. This is based on a variety of factors, including an increase in software and, therefore, vulnerabilities, as well as a change in interagency support.
March 8th analysis by Linux Foundation's OpenSSF, https://www.securityweek.com/cve-and-nvd-a-weak-and-fracture... & https://www.linkedin.com/posts/netriseinc_cve-vulnerabilitym... (graph)> Starting February 12th, thousands of CVE IDs have been published without any record of analysis by NVD. Since the start of 2024 there have been a total of 6,171 total CVE IDs with only 3,625 being enriched by NVD. That leaves a gap of 2,546 (42%!) IDs.
Private/paid offerings? https://www.darkreading.com/vulnerabilities-threats/nist-nee...
> NIST is going to open up the program to a consortia of vetted organizations from the industry in order to deal with the backlog of vulnerabilities that need to be analyzed.. Budget cuts happening for the first time in a decade.. hopefully a pivot to a private-public sector partnership can be reached quickly to scale up the program
OSS alternative to paid offerings? April 2024 open letter from Yocto, https://github.com/yoctoproject/cve-cna-open-letter/blob/mai...
Processes/tooling to easily allow CNAs to adopt enhancements to CVEs would also encourage improving the data, ideally as easy as something like a GitHub pull request. We, as projects that need to respond to security issues, could all do things in our own ways. Many of us have open source backgrounds and realise the power of collaboration and would much prefer to work together and build something none of us alone could achieve. We need the tools, processes and core support from the CVE project to make it happen.