- Government ceases funding MITRE for CVE oversight.
- Uncertain future created by DOGE-style cuts.
- Collective cybersecurity efforts left rudderless.
The MITRE organisation has not had its contract renewed by the US Department of Homeland Security to continue its work on the CVE oversight programme. The cessation of funding comes as part of the US government’s budget-cutting measures.
The world’s CVE programme (Common Vulnerabilities and Exposures) has been, until today, managed by MITRE, and the cut in funding leaves the cybersecurity world with no central, trusted authority to categorise and publicise cybersecurity issues, flaws, and advisories.
Having a centralised resource that assesses, ranks, and publishes the world’s security researchers’ findings means that there’s no accepted yardstick with which to assess a bug or flaw’s seriousness, and implies that mitigation efforts may be duplicated.
The death of CVE oversight
In a leaked letter to CVE board members, Yosry Barsoum, Director of the US’s Center for Securing the Homeland, said, “the current contracting pathway for MITRE to develop, operate, and modernize CVE and several other related programs, such as CWE [common weakness enumeration], will expire. […] If a break in service were to occur, we anticipate multiple impacts to CVE, including deterioration of national vulnerability databases and advisories, tool vendors, incident response operations, and all manner of critical infrastructure.”
Cybersecurity professionals from all over the world have expressed their dismay. Brian Krebs (Krebs on Security) wrote on Mastodon, “It’s worth asking again who would benefit from taking CVE offline? […] it almost certainly would help our adversaries […] because confusion and uncertainty works to their advantage always.”
“Without [CVEs], we can’t track newly discovered vulnerabilities. We can’t score their severity or predict their exploitation. And we certainly wouldn’t be able to make the best decisions regarding patching them,” said Sasha Romanosky, a researcher at Rand Corporation, speaking to CSO Online.
“Losing it will make our software harder to secure, and its absence will mark a victory for cybercriminals across the world. It feels possible that funding for this will move to one of the big players in global cybersecurity, or perhaps a consortium of them, as the health of the CVE MITRE database is undoubtedly of global benefit,” said Matt Saunders, devops lead at The Adaptavist Group.
The reasons behind swingeing cutbacks to a not-for-profit organisation at the centre of world efforts to combat cybersecurity are incredibly difficult to imagine in a universe that respects logic.
Brian Krebbs’s Mastodon thread suggested the villain in the piece is Elon Musk’s DOGE, stating, “Probably the last CVE indexed before it goes dark should be CVE-2025-DOGE (critical, local privilege escalation vulnerability that leads to malicious code execution and data exfiltration).”
CVE oversight – an uncertain future
Several commentators have expressed hope that a well-known industry organisation might fund or take over the management of the CVE project. Were that to be the case, it would be critical that those financing the project allow its contributors the necessary independence and objectivity – those are the aspects of operations to date that have allowed the CVE programme to become a trusted reference point for cybersecurity globally.
The danger to the cybersecurity community (and all users of any form of computing) is that a new administrating organisation regards its new ward as a commercial opportunity, rather than a necessity for the common good. Given the current political climate, in which large technology companies are granted increasingly free rein, reliable stewardship is not a certainty.
Author
- View all posts
Joe Green is a writer based in Bristol, UK. He acquired his first computer with dial-up modem in 1992 and has worked in the tech industry since 2000. He writes and podcasts, specialising in open-source, networking, cybersecurity, software development and online privacy.