Question Regarding CVE Assignment Timeline for GitHub Security Advisories #202641
Unanswered
Char0n1507
asked this question in
Code Security
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
🏷️ Discussion Type
Question
💬 Feature/Topic Area
Other
Discussion Details
Hi everyone,
I'm looking for some clarification regarding the current timeline for CVE assignments through GitHub Security Advisories.
I recently reported a vulnerability to an open-source project, and the maintainers were very responsive. The issue has been fixed, the advisory has been published, and a CVE request was submitted through GitHub's CNA process.
According to the advisory timeline:
The report was accepted by the maintainers.
The advisory was published.
A CVE was requested through GitHub.
The request is currently awaiting review.
I understand that processing times can vary depending on workload, and I appreciate the efforts of the GitHub CNA team. However, I was hoping to better understand the current expectations for CVE assignment timelines.
A few questions:
Are there currently any known delays or backlogs affecting CVE assignments?
Is it normal for requests to remain pending beyond the estimated review period shown in the advisory?
Is there a recommended way to check the status of a CVE request after it has been submitted?
At what point would it be appropriate to contact GitHub Support regarding a pending assignment?
I am not seeking information about the specific vulnerability itself, only guidance on the CVE assignment process and expected timelines.
Thank you to anyone who can provide insight.
Beta Was this translation helpful? Give feedback.
All reactions