NIST No Longer Enriching CVEs, Signaling Industry-Wide Shift Away from NVD.
Blog post from Semgrep
On April 15th, NIST announced significant changes to the National Vulnerability Database (NVD) management of software vulnerabilities, citing an inability to keep up with increased CVE submissions. This shift means the NVD will stop enriching most open source vulnerabilities, impacting the Software Composition Analysis (SCA) market and forcing vendors to reconsider their vulnerability management strategies, which have traditionally relied on NVD's CVSS scores. Semgrep has already adapted by using GitHub Security Advisories as a data source, focusing on reachability and detailed metadata for prioritization. Security leaders are advised to update compliance documents referencing NVD CVSS scores, prioritize beyond raw CVSS, and query vendors on their data sources in response to NVD's changes. These adjustments present an opportunity for security teams to adopt reachability-based approaches, reducing noise and enhancing risk management by focusing on impact-based prioritization for a more secure future in application security.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.