oss-sec mailing list archives
Becoming a CVE Naming Authority for your project
From: Rodrigo Freire <rfreire () redhat com>
Date: Tue, 4 Nov 2025 08:47:35 -0300
Open Source Project Maintainers, Managing security vulnerabilities is currently a significant pain, especially with the recent increase in dubious CVE reports due to AI assistants. The discussion around questionable CVEs reported against projects like dnsmasq, curl highlights a growing concern within the open source community. One effective way to combat the influx of bogus CVEs and ensure accurate vulnerability reporting is for open source projects to become their own CVE Numbering Authority (CNA). As a CNA, your project gains control over the CVE assignment process. Taking ownership of your project's as a CNA ensures that you are in control of the CVE assignment. There will be some requirements to it, sure thing. Check https://openssf.org/blog/2023/11/27/openssf-introduces-guide-to-becoming-a-cve-numbering-authority-as-an-open-source-project/ If you want to learn more and how it impacted an open source project, reach for the glibc (in the past, a frequent topic here in this mailing list) security community (https://sourceware.org/glibc/security.html) and ask them your questions. If you're interested in learning more about becoming a CNA, Red Hat (along Google, INCIBE, JPCERT/CC, and Thales Group) can help you. Reach ymittal () redhat com and we will be happy to help. Best regards; Rodrigo Freire Chief Architect
Current thread:
- Becoming a CVE Naming Authority for your project Rodrigo Freire (Nov 04)
- Re: Becoming a CVE Naming Authority for your project Greg KH (Nov 04)
- Re: Becoming a CVE Naming Authority for your project Olle E. Johansson (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Pedro Sampaio (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Peter Gutmann (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Matthew Fernandez (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Art Manion (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Pedro Sampaio (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Olle E. Johansson (Nov 06)
- Re: Becoming a CVE Naming Authority for your project Peter Gutmann (Nov 07)
- Re: Becoming a CVE Naming Authority for your project Olle E. Johansson (Nov 05)
- Re: Becoming a CVE Naming Authority for your project Greg KH (Nov 04)
