Home / Companies / Semgrep / Blog / Post Details
Content Deep Dive

NIST No Longer Enriching CVEs, Signaling Industry-Wide Shift Away from NVD.

Blog post from Semgrep

Post Details
Company
Date Published
Author
Nabeel Saeed
Word Count
616
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

On April 15th, NIST announced significant changes to the National Vulnerability Database (NVD) management of software vulnerabilities, citing an inability to keep up with increased CVE submissions. This shift means the NVD will stop enriching most open source vulnerabilities, impacting the Software Composition Analysis (SCA) market and forcing vendors to reconsider their vulnerability management strategies, which have traditionally relied on NVD's CVSS scores. Semgrep has already adapted by using GitHub Security Advisories as a data source, focusing on reachability and detailed metadata for prioritization. Security leaders are advised to update compliance documents referencing NVD CVSS scores, prioritize beyond raw CVSS, and query vendors on their data sources in response to NVD's changes. These adjustments present an opportunity for security teams to adopt reachability-based approaches, reducing noise and enhancing risk management by focusing on impact-based prioritization for a more secure future in application security.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.