Identifies the misalignment between the commercial CVE system and open-source maintenance, highlighting the risk of maintainer burnout from AI-generated vulnerability noise.
The CVE system, originally designed for commercial vendor-customer relationships, is increasingly ill-suited for the open-source ecosystem where maintainers are volunteers. In 2023, 28,831 CVEs were reported—up from 16,510 in 2018—driven partly by jobseekers and AI tools flooding projects with bogus reports to pad resumes. Maintainers are increasingly caught in a cycle of 'terror reporting' where low-signal or non-exploitable bugs (e.g., Jackson Databind and cURL incidents) are marked as critical by scanners, leading to harassment and burnout. The report advocates for shifting the verification burden from maintainers back to reporters and CNAs, and warns that treating volunteers like commercial vendors with strict SLAs is driving many to abandon the open-source ecosystem entirely.
Maintainers are caught combating misinformation or dealing with unrealistic expectations and abuse... turning security bug report triage into 'terror reporting'.
Risk Guard relies on formal CVE records but does not factor in 'Maintainer Dissent' or cases where a CVE is triaged by the project as 'Invalid' or 'Not a Vulnerability'.
Risk Guard would be better if it cross-referenced 'Disputed' flags from the original repository's issue tracker to avoid penalizing maintainers for bogus CVEs.