The Growing Crisis in CVE Data Quality
Jerry Gamblin
BSidesSF 2025 — Here Be Dragons · Day 2 · Main
Overview
The CVE program is the backbone of global vulnerability management — but its data quality is deteriorating under the weight of exploding volume, underfunded enrichment, and minimal publishing requirements that allow nearly useless records to enter the system legally. Jerry Gamblin of Cisco, who runs the CVE tracking site cve.icu, diagnoses the structural failures behind the crisis and calls on the security community to demand mandatory quality fields, engage CVE working groups, and pressure CNAs to publish data that is actually usable. ---

Key moments
- 0:00 CVE funding near-collapse: $29M contract almost lapsed with zero public warning
- 1:59 Three new CVE databases launched within 12 hours during funding panic
- 7:59 Shocking minimum bar: 2-char description plus N/A product is a legally valid CVE
- 9:59 20% of all CVEs fail their own minimum guidelines; NVD abandoned enrichment effort
- 11:59 Only 50% of CVEs have any CVSS score; last 18 months only 25% enriched by NVD
- 14:00 Cost revelation: US government pays $1,237 per new CVE across MITRE and NVD
- 20:00 Call to action: push for mandatory CVSS, CPE, CWE fields and join working groups
The Growing Crisis in CVE Data Quality
Speaker: Jerry Gamblin
Conference: BSidesSF 2025 — April 26-27, 2025, San Francisco
YouTube: https://www.youtube.com/watch?v=t-DJZuKbigo
Reading time: ~7 minutes
TL;DR
The CVE program is the backbone of global vulnerability management — but its data quality is deteriorating under the weight of exploding volume, underfunded enrichment, and minimal publishing requirements that allow nearly useless records to enter the system legally. Jerry Gamblin of Cisco, who runs the CVE tracking site cve.icu, diagnoses the structural failures behind the crisis and calls on the security community to demand mandatory quality fields, engage CVE working groups, and pressure CNAs to publish data that is actually usable.
Introduction
The CVE program nearly collapsed in April 2025. A leaked letter revealed that MITRE's contract to run the program — funded at $29 million per year through CISA and the Department of Homeland Security — was at risk of lapsing. In the 12 to 18 hours the situation was uncertain, three alternative CVE databases emerged: one from ENISA (the EU's CISA equivalent), one from CIRCL (Luxembourg's CERT team, branded as the Global CVE or GCVE), and one from a newly formed foundation seeking to take over the program from US government control. Within days the funding was reinstated — with the government subsequently claiming there had been no issue at all.
Jerry Gamblin lived through that episode up close, and at BSidesSF 2025 he used it as a prologue to the problem he actually wanted to talk about: not whether the CVE program will survive, but whether, in its current state, it deserves to. The data quality crisis in the CVE ecosystem has been building for years, and the near-collapse only interrupted a presentation that was already about to diagnose a slower, less dramatic failure.
The CVE System: A Bureaucracy on a Bureaucracy
▶ Watch: How the CVE funding and governance chain works (02:00)
To understand why CVE quality is hard to fix, it helps to understand how the money and authority flow. The Department of Homeland Security funds CISA, which funds the Homeland Security Systems Engineering and Development Institute (HSSEDI), which contracts with MITRE, which runs the CVE program — including its published database at cve.org and its administration of the CNA (CVE Numbering Authority) system. That chain carries a contract valued at $29 million per year.
Separately, NIST runs the National Vulnerability Database (NVD), which enriches CVE records with CVSS scores, CPE (Common Platform Enumeration) data, and CWE (Common Weakness Enumeration) classifications. NIST's NVD work is contracted through a company called Analigence at a value of $125 million over five years — roughly $25 million annually. Between the two programs, the US government spends approximately $1,237 per newly published CVE when measured against the 2025 publication rate, or $188 per record per year when calculated across the full existing database of nearly 291,000 CVEs.
The structural problem: MITRE's mandate is to publish CVEs; NIST's mandate is to enrich them for the federal government, not for the broader security community. When the community raises quality concerns, both organizations can — and do — point out that their mandate is not to serve the public. As Gamblin notes, the question of why NIST, a standards body, is running what is functionally a vulnerability intelligence service for the global security industry is one that nobody has ever given him a satisfying answer to.
The Quality Problem: What a "Valid" CVE Actually Looks Like
▶ Watch: CVE publishing requirements and quality failures (06:00)
Publishing a CVE requires four fields: an ID, a description, a product, and a version. The description requires a minimum of two characters and a maximum of 4,096. The product and version fields accept "N/A" as valid input. This means a CVE with the description "spoofing vulnerability," product "N/A," and version "N/A" fully satisfies the current requirements and will be accepted into the database.
This is not a theoretical edge case. Gamblin showed a real Microsoft-published CVE containing only "Spoofing Vulnerability" as its description — no affected product, no version range, no CVSS score, no CWE. Around 20% of all CVEs use N/A for the product field. The NVD's own enrichment process — which would add CVSS scores, CPE, and CWE — has fallen so far behind volume that only about one quarter of CVEs published in the last 18 months have NVD-supplied CVSS scores. Out of 291,000 total CVEs in the database, approximately 24,000 have no CVSS score, no CPE, and no CWE from NVD.
In March 2025, NIST formally acknowledged it could not keep pace with the publication rate and announced it would no longer attempt to provide complete enrichment coverage. The data quality problem, in other words, is not a temporary backlog — it is a structural admission that the enrichment function has been abandoned.
The Volume Problem: 30% Growth Year-over-Year
▶ Watch: CVE volume trends and the forecasting community (06:00)
CVE volume is growing at approximately 30% year-over-year. As of the date of Gamblin's talk, the 2025 total had already exceeded 15,000 — compared to just over 12,000 at the same point in 2024. This growth is accelerating, driven in part by the expansion of the CNA program, which allows individual companies and organizations to publish their own CVEs without going through MITRE.
One illustrative data point: for the first time in the CVE program's 25-year history, a single CNA — Patchstack, which focuses exclusively on WordPress plugin vulnerabilities — is on track to publish more CVEs in 2025 than MITRE itself. Approximately 90% of Patchstack's CVEs are cross-site scripting vulnerabilities in WordPress plugins. Gamblin is measured on this: the data is good, the records are complete, and the vulnerabilities are real. Volume alone is not the crisis. Volume combined with inadequate quality standards and collapsing enrichment infrastructure is.
Privatization and Fragmentation: GitHub, Google, and Geopolitics
▶ Watch: Alternative databases and the fragmentation risk (16:03)
The quality gap has prompted major technology companies to build their own parallel vulnerability databases. GitHub Advisory Database and Google's OSV (Open Source Vulnerability) database both maintain high-quality, well-structured records — and their coverage overlaps minimally with each other and with the NVD. For practitioners, this means checking multiple databases to get a complete picture of exposure.
The geopolitical dimension adds another layer of fragmentation. China operates its own National Vulnerability Database (CNVD), and Russia operates an equivalent. Gamblin reports that from his location in the US, the Chinese vulnerability database is not accessible; he presumes the NVD is similarly inaccessible from Russia. A global vulnerability catalog that is partitioned by geopolitics is a catalog that cannot fully serve its purpose — particularly for multinational organizations trying to understand their exposure across environments.
The fragmentation risk from the near-funding-collapse was immediate and stark: three new databases in 18 hours. Gamblin's view is that the CVE system is worth preserving precisely because it is already established as the universal reference standard. Replacing it with a cluster of competing databases would make vulnerability management harder for every organization that currently relies on CVE IDs as the common language of vulnerability disclosure.
Notable Quotes
"There is no DR plan if the CVE program goes away. We will be in a wait and see mode. Luckily, in that same period, they reinstated the funding with zero public announcement that the funding had been in danger."
— Jerry Gamblin [[▶ 00:00]](https://www.youtube.com/watch?v=t-DJZuKbigo&t=0s)
"You could file a CVE today that says 'spoofing vulnerability' with the product N/A and the version N/A, and that would pass all the requirements for the CVE program as of today."
— Jerry Gamblin [[▶ 08:01]](https://www.youtube.com/watch?v=t-DJZuKbigo&t=481s)
"Would you rather have a hundred percent of the fields filled in with ninety percent correctness, or have them all marked null? That is a decision we're going to have to make as a group."
— Jerry Gamblin [[▶ 26:03]](https://www.youtube.com/watch?v=t-DJZuKbigo&t=1563s)
Key Takeaways
- The CVE program's data quality problem is structural, not temporary. NIST has formally acknowledged it cannot enrich CVEs at the current publication rate. Only about half of all published CVEs have any CVSS score or CWE classification, and the gap is widening.
- "Valid" CVE records can be nearly useless. Current publishing requirements allow records with two-character descriptions and N/A for both product and version. Twenty percent of all CVEs exploit this gap.
- Volume is accelerating the crisis. CVE publications are growing 30% year-over-year. A single WordPress-focused CNA is on track to publish more CVEs in 2025 than MITRE itself.
- Fragmentation is the existential risk. Competing databases from GitHub, Google, ENISA, and others are filling the gap — but with minimal overlap and varying quality standards. A fractured vulnerability reference system is worse for defenders than an imperfect unified one.
- The community can push for change. Gamblin calls for mandatory CVSS, CPE, and CWE fields in all published CVEs; engagement with the CVE program's open working groups (including a forthcoming consumer working group); and direct pressure on CNAs that publish low-quality records to enrich their data to the standard they already use in their own advisories.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Gamblin comes with data, not opinions: 20% of all CVEs use N/A for the product field, only a quarter of CVEs published in the last 18 months have NVD CVSS scores, NIST formally admitted it can no longer keep pace with volume, and the program nearly went dark in April 2025. This is the kind of systemic critique that only lands when the critic has actually run the numbers — and Gamblin runs cve.icu, so he has.
Heather Calloway (CISO) — MUST SEE
The CVE program is critical infrastructure for the global security community, and it is quietly failing — not from a funding crisis but from a standards crisis that nobody in the governance chain is accountable for fixing. Gamblin names the problem with specificity, explains the structural reasons it persists, and tells defenders exactly what they can do about it. This is the governance story the community needs to be having.