THREATOPS
THREAT OPSThreat News › Re: Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely

Re: Reporter attribution is absent from GitHub's machine-readable vulnerability records, and from the NVD entirely

medoss_secPublished 2026-08-27

<p>Posted by Greg KH on Aug 26</p>Yes, cve.org json records are known to have this issue, because almost<br /> all fields are not required. Unless cve.org makes this a requirement,<br /> any CNA is free to not populate the fields if they so desire.<br /> <br /> github isn&apos;t the only CNA that doesn&apos;t do this, most don&apos;t, for various<br /> reasons (not the least being the amount of s

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/599