logo

NVD slowdown leaves thousands of vulnerabilities without analysis data

ID: 20b6a583-3614-5152-a8c2-0c28b42d636c

STIX ID: report--20b6a583-3614-5152-a8c2-0c28b42d636c

Feed Name: The Register (Security)

Date Published: 2024-03-22

Date Updated: 2026-04-26

Author: Steven J. Vaughan-Nichols

...
...

The article argues that since February 15, 2024, NIST’s NVD has largely paused analysis and enrichment of newly published CVEs, leaving thousands without CWEs, CPEs, or CVSS, which disrupts scanners, risk workflows, and U.S. federal compliance that mandate NVD data; while alternatives (OSV, GitHub advisories) and community stopgaps (Anchore’s NVD Data Overrides) exist, none match NVD’s breadth, raising concerns that under-resourcing at NIST is degrading a critical piece of security infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.