Provides a case study of 'CVE inflation' and the disruptive effects of automated reporting bots on open-source maintainers and downstream security triage.
The `node-ip` project, which receives over 16 million weekly downloads, was temporarily archived by its maintainer in 2024 in protest of a 'dubious' critical 9.8 CVE rating. The maintainer, a former Node.js TSC member, argued that the vulnerability (CVE-2023-42282) was marginal and that the verification process for commercial advisories often excludes maintainers, leading to exaggerated ratings that create 'noise and chaos' for developers. GitHub eventually revised the severity down to 'Low', echoing similar disputes in other major projects like `curl`, `PostgreSQL`, and `micromatch` (64M weekly downloads) where theoretical bugs were reported as high-severity security flaws by automated scanners.
CVE-2023-42282 affected specific versions of the node-ip package (16M weekly downloads), triggering widespread alerts and a maintainer protest over severity scoring.
false urgency or missed genuine risk when version-specific vulnerability data is consumed without context about dispute status or severity revisions
identifying known vulnerabilities in the specific version being consumed is the foundational signal — the node-ip case demonstrates both its value and the need for accurate severity data.
The verification process of vulnerability reports doesn't involve maintainer at all... commercial interest of advisory repositories is aligned with creating more vulnerabilities.
Risk Guard treats all CVEs from major databases as authoritative but doesn't track whether a CVE is 'Disputed' by the maintainer in the original repository.
Risk Guard would be better if it cross-referenced CVEs with GitHub Issues/Discussions to detect maintainer disputes and adjust risk scores accordingly.