Home / Companies / Socket / Blog / Post Details
Content Deep Dive

NVD Quietly Sweeps 100K+ CVEs Into a “Deferred” Black Hole -...

Blog post from Socket

Post Details
Company
Date Published
Author
Sarah Gooding
Word Count
912
Company Posts That Month
27
Language
English
Hacker News Points
-
Post removed?
No
Summary

The National Vulnerability Database (NVD) has begun designating over 100,000 pre-2018 Common Vulnerabilities and Exposures (CVEs) as "Deferred," indicating a halt in updating these older vulnerabilities with essential metadata such as CVSS scores and CWE classifications. This move, which has already reclassified 20,000 CVEs overnight, aims to clarify prioritization but has sparked concern and criticism from the security community due to a lack of transparency and the potential risk it poses by obscuring the true scale of unaddressed vulnerabilities. Critics argue that this reclassification reduces the apparent backlog without addressing underlying issues, leading to less comprehensive and reliable public data. As the NVD's role as a central source of vulnerability information becomes increasingly strained, security teams are urged to diversify their information sources and automate metadata enrichment to mitigate the operational risks associated with relying solely on NVD data.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.