Risky Bulletin Newsletter
September 01, 2023
Risky Biz News: Open-source projects plagued by rash of fake or disputed CVEs
Presented by

News Editor
An anonymous researcher has sifted through the changelogs of open-source projects and obtained CVE identifiers for old bugs that experts say may not be security flaws.
All the fake CVEs were obtained on August 22nd, and all were filed for open-source projects.
According to a list compiled by Chainguard at RiskyBusiness' request, 138 CVEs were filed in projects such as cURL, PostgreSQL, Python, the Netwide Assembler, ImageMagick, and many smaller libraries.