Google’s OSV Fix Just Added 500+ New Advisories — All Thanks to One Small Policy Change
Blog post from Socket
A recent policy change in Google's Open Source Vulnerabilities (OSV) database led to the addition of 500–600 new advisories, addressing a longstanding issue of treating "disputed" CVEs as "withdrawn," which previously obscured real vulnerabilities from users relying on the data feed. This issue was highlighted by the exploitation of CVE-2023-48022, a disputed vulnerability in Anyscale's Ray, which was actively exploited despite being marked as withdrawn in OSV's feed. The problem was brought to light by a discrepancy between trusted databases, prompting a revision in OSV's approach to allow disputed CVEs to be visible rather than suppressed. This correction restored visibility to numerous vulnerabilities and underscored the fragility of vulnerability intelligence pipelines, as misinterpretations can lead to significant data suppression and real-world security risks. The case also highlighted the need for more transparent handling of disputed vulnerabilities to avoid alienating security researchers and users who depend on accurate data.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.