CVE Foundation
thecvefoundation.org
thecvefoundation.org
https://www.forbes.com/sites/kateoflahertyuk/2025/04/16/cve-...
Supposedly, MITRE will make a statement today. Time will tell.
Edit - it is MITRE, not CISA, which the poster expects to make a statement.
Metacurity’s post was like 90 minutes ago.
> However, in an updated statement, the agency revealed it intends to maintain the database in a bid to prevent a lapse in CVE services.
> “The CVE Program is invaluable to the cyber community and a priority of CISA,” a spokesperson said.
> “Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners’ and stakeholders’ patience.”
Searching for that last passage:
https://www.bleepingcomputer.com/news/security/cisa-extends-...
> "The CVE Program is invaluable to cyber community and a priority of CISA," the U.S. cybersecurity agency told BleepingComputer. "Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services. We appreciate our partners' and stakeholders' patience."
And https://www.reuters.com/world/us/us-agency-extends-support-l...
> WASHINGTON, April 16 (Reuters) - U.S. officials have said at the last minute that they're extending support for a critical database of cyber weaknesses whose funding was due to run out on Wednesday.
> The planned lapse in payments for the MITRE Corp's Common Vulnerabilities and Exposures database spread alarm across the cybersecurity community. The database, which acts as a kind of catalog for cyber weaknesses, plays a key role in enabling IT administrators to quickly flag and triage the myriad different bugs and hacks discovered daily.
I don't believe it was a mistake - they wanted to pull its funding (and still intend to do). Note the wording of the statement:
> Last night, CISA executed the option period on the contract to ensure there will be no lapse in critical CVE services.
We are now in the option period.
At some point in the future, that option period will expire.
https://www.cisa.gov/news-events/directives/bod-22-01-reduci...
A binding operational directive is a compulsory direction to federal, executive branch, departments and agencies for purposes of safeguarding federal information and information systems.
Section 3553(b)(2) of title 44, U.S. Code, authorizes the Secretary of the Department of Homeland Security (DHS) to develop and oversee the implementation of binding operational directives.
Federal agencies are required to comply with DHS-developed directives.
...
Remediate each vulnerability according to the timelines set forth in the CISA-managed vulnerability catalog. The catalog will list exploited vulnerabilities that carry significant risk to the federal enterprise with the requirement to remediate within 6 months for vulnerabilities with a Common Vulnerabilities and Exposures (CVE) ID assigned prior to 2021 and within two weeks for all other vulnerabilities. These default timelines may be adjusted in the case of grave risk to the Federal Enterprise.
If there's no catalog that the government is maintaining for "these things need to be fixed to run on federal systems" ... then how do you ensure that the federal computers are secure?Assuming this is the correct contract, which it appears to be, it had an option period starting today through March of next year. DHS just needed to exercise the option.
https://old.reddit.com/r/netsec/comments/1k0dodx/mitre_suppo...
Here is a LinkedIn post by one of the CVE board members (literally the first one on the list here[0]): https://www.linkedin.com/posts/peterallor_cve-foundation-act...
I'm sure if you look at some of the contact information of other CVE board members and their broadcasting platforms you will also find something.
How much more of a "clear confirmation" do you want? An announcement from their non-existent personal press secretaries that just says the exact same text as that post he boosted?
I think people here need to take a step back and realize that the people and board involved here are more like linux kernel maintainers that are not generally public figures and not C-level executives of a Fortune 500 company.
Yes, since it's cybersecurity a bit more caution than usual is probably warranted, but it's not like the CVE DB has gone offline and everyone is currently scrambling to find the new legitimate replacement. Let's let this situation breathe for a few hours/days instead of being overly cautious and spending all energy on skepticism.
Given the state of trustworthy information in news and public discourse, it's understandable that people request a credible source.
The thing called "social media" ain't it.
CVE program faces swift end after DHS fails to renew contract [fixed] - https://news.ycombinator.com/item?id=43700607
Replacing CVE - https://news.ycombinator.com/item?id=43708409
They have the means. With their massive revenue and dedicated security teams, these companies could easily fund CVE operations. A consortium approach spreads responsibility fairly;
Shared responsibility, shared benefits. Security is everyone's problem.
In general, lawyers and CTOs would probably love to see CVE go away or be taken over by industry.
Source: been working in security for 20+ years.
To anyone who thinks a libertarian/anarcho-capitalist/Network States "utopia" of Retire All Gubberment Employees (RAGE) is a "good thing", thing about air, water, and soil pollution from sewage to arsenic to particulates to lead to radioactivity. Greedy sociopaths DGAF who they hurt, which is perhaps why James Madison observed: "If all men were angels, no government would be necessary." Obviously, this is not human nature and so some laws, enforcement, and regulators is required indefinitely. Anyone who tells you differently isn't a serious person.
While they are at it maybe chuck $5 to the dev maintaining the open source package that your trillion dollar corporation relies on, that your 50,000 leetcoders can't figure out how to write or live without.
We used to look at cert: https://www.kb.cert.org/vuls/ I just did a quick search to confirm that it is still there.
What's the difference/relationship between the two?
I suspect some likely fracturing of efforts here. Would be great if everyone did get behind a single solution. I’m not sure if this is it. A US-based non-profit is not maybe the best solution.
Cloudstrike turned into the worst peice of garbage since waferlocks...
The single most profitable source of forien funds for N Korea turns out to be stolen vit-xoins, while gov officials are forciblly removed from their desks...
What. Me. Worry?
I don't think it's credible that CVE as an organisation would produce this website and not link to it from their official site or social media accounts.
In response, a coalition ..."
This sounds like secret, unofficial contingency planning; "this day" has apparently come very suddenly.
Original comment:
Why is this being upvoted? There's no reference to it on the CVE website and the domain was only registered after the letter leaked despite the website claiming this was in the works for a year.
Additionally the WHOIS claims that the registrant is "CVE Foundation" which can not be found using the IRS search tool for tax-exempt organisations (note that MITRE does show up here): https://apps.irs.gov/app/eos/
Not, "All your updates are belong to us."
And...
A personal thanks to every security researcher who has contributed. In.The last year. I see a CVE, and specifically look for the out-or-band update and patch everything that powers up.
One breach on an old ladies laptop, who had the sence to bring it right to me. Keep those covers on the cameras folks.
Who runs this thing? Who's funding it? Who's reviewing, testing, and approving the reports? Assigning them IDs?
I'm hoping for the best, and I'm willing to give the benefit of the doubt because of the frankly crap timing around this whole mess, but on its face, in its current state, I wouldn't trust this org at all.
No thanks.
Harvard for example doesn't kow-tow to the reigime, and look what happens. Non-profits in the USA are not independent.
Maybe CVEs should be tracked by a nongovernmental agency, like how UL works.
The problem is the seat of the non-profit, as long as it is in the US it remains vulnerable to stuff like gag orders (and the UK is similar, see the recent issues with Apple and E2E encryption), or just the administration plainly ignoring the law and just forcing it to shut down or whatnot.
> Maybe CVEs should be tracked by a nongovernmental agency, like how UL works.
The current administration has attacked multiple nongovernmental agencies already, or trampled over federal law.
The only thing I'd trust for now to be a safe haven would be an international organization like the WHO that's backed by diplomatic treaties - but even these aren't safe either, just look at the ICC vs Israel debate, or the constant attacks and conspiracy theories on the WHO.
Only under FISA warrants where you can't reveal the investigation to the public or during a regular trial if the judge determines leaking details of the case will impact justice AFAIK.
OK well we know where you stand on that issue. Too bad pretty much every working molecular biologist agrees that the WHO is covering up COVID origins.