Warns of the decreasing reliability of vulnerability databases due to automated bots filing bogus CVE reports from old resolved bugs.
The CVE database is increasingly targeted by automated bots and AI tools that scrape old issues and commits to file bogus or irrelevant vulnerability records without maintainer involvement. A recent surge saw 138 new 'vulnerabilities' entered into open-source projects on a single day, including a 2019 curl bug (CVE-2020-19909) that was incorrectly categorized as a new critical integer overflow years after it was fixed. These automated submissions create significant noise for security teams, as many scanners disregard the 'DISPUTED' status, wasting triage resources on non-issues while actual vulnerabilities remain unaddressed.
Filing vulnerabilities that are in fact bugs that were resolved long ago is a weird form of fear mongering... scanners will not see or disregard the 'DISPUTED' status.
Risk Guard trusts CVE status but does not currently account for 'Disputed' flags or the historical accuracy of a CVE reporter.
Risk Guard would be better if it verified the 'Disputed' status of CVEs and factored in maintainer feedback to reduce false positives from automated reporting bots.