CVE assignment pending past 72-hour SLA for published advisory #200225
Replies: 4 comments 5 replies
-
|
I've been experiencing the same issue. It's has been like 108hrs since reported vulnerabilities CVE request sent to GitHub. I'll be following this discussion to see what is causing this issue |
Beta Was this translation helpful? Give feedback.
-
|
Same applied on my end I have the similar experience on some of my reports |
Beta Was this translation helpful? Give feedback.
-
|
Same. I was facing the same issues. Not only the CVE assignment delay issue, but also the CVE publish delay issue. So, it looks like a huge backlog for CVEs. I believe the backlog will impact the downstream users, the high risk to expose the downstream users without any notices. |
Beta Was this translation helpful? Give feedback.
-
|
@mgriffin any updates 😔 |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Discussion Type
Question
Discussion Content
Hi everyone,
I'm reaching out to see if anyone else has been experiencing unusual delays with CVE ID assignments recently, or if there's a recommended way to unblock stalled requests.
Over the past few weeks I've been conducting vulnerability research and responsibly disclosing several issues. The maintainers have requested CVE IDs through GitHub's CNA, but the requests appear to be stalled.
These requests were submitted over four days ago, which is well beyond the typical 72-hour SLA. None of the advisories have received any updates, requests for additional information, or CVE assignments. Since the advisories are already public, we're hoping to have the corresponding CVE IDs assigned as soon as possible so downstream users and security tools can properly track the vulnerabilities.
I have a few questions for the community or any GitHub staff who may be able to help:
(I'm happy to provide direct links if needed.)
Any guidance or assistance would be greatly appreciated. Thank you!
Beta Was this translation helpful? Give feedback.
All reactions