Skip to content

The Cathedral and the Bazaar of Software Vulnerabilities: From the NVD to the CNAs #50

Description

@SiqiZhang0510

Proposed Discussion Topic

We recently released an arXiv paper:

The Cathedral and the Bazaar of Software Vulnerabilities: From the NVD to the CNAs

Abstract

For decades, the National Vulnerability Database (NVD), the "Cathedral", has been the reference source for vulnerability information for downstream research and industry tasks, e.g., software update prioritization. An emerging "Bazaar" of diverse CVE Numbering Authorities (CNAs) has created many alternative and sometimes diverging sources. We conduct a systematic analysis of divergence in Common Vulnerability Scoring System (CVSS) metrics covering the NVD and the public CNAs. We also check for self-divergence: two identical textual descriptions of CVEs with identical CWEs are rated differently by the same CNA. The odds of divergence are widespread, not uniform and sometimes unexpected. The assessment of Attack Complexity, User Interaction, and Impact are the major metrics where divergence happens. To understand the root causes, we perform a qualitative study by reaching out to the NVD and other CNAs (both open sources and proprietary products). We also discussed the findings at the CVSS Special Interest Group of FIRST, the community responsible for maintaining and evolving the CVSS standard. The key insights are that while something might be due to human errors, in some cases diverging is actually the right thing to do and might require changes in the way CVEs are generated industry-wide, in other cases explaining divergence requires access to additional FAQs. The good news is that the situation is improving since 2025, the bad news is that if one downloads the whole NVD (or another CNA dataset) from several years and uses it for predictions, the models trained on one source do not reliably generalize to a different source (accuracy can drop by 40%). We discuss the implications for practice and research.

Our Studies

First, we introduce a framework for characterizing two types of CVSS divergence: cross-source divergence, which compares CVSS assessments assigned by CNAs and the NVD for the same CVE, and self-divergence, which identifies situations where the same source assigns different CVSS vectors to vulnerabilities with identical descriptions (further refined using CWE/CPE context).

Second, we perform the first large-scale empirical study of these two forms of divergence across the NVD and public CNAs, revealing where and how often disagreements occur.

Third, we investigate the factors associated with divergence using statistical regression analyses, examining the effects of CNA type, assessment order, CWE consistency, description quality, and other characteristics.

Finally, we complement the quantitative analysis with discussions involving NVD analysts, several CNA representatives, and the FIRST CVSS SIG to understand the potential root causes of divergence and their implications for the broader CVE ecosystem.

Paper:
http://arxiv.org/abs/2607.05670

Activity

  1. FabioMassacci commented on Jul 9, 2026

    @FabioMassacci

    The problem for discussion in not that there are divergent CVSS scores (sometimes divergent is really due to technical configuration information), but that such divergence is unexplained.

    There are two actionable topics for the CVE Quality

    • downstream CNAs that use the same software *e.g. version of Linux, cannot enrich their CVE entry with some additional info that explain the different score, this could be addressed by making possible for CNA to add the CVSS score and some text (this would require to change the format).
    • the text used by some CNA is often identical and too terse, this could be addressed by checking that the CVE description should have a fragment of sentence for each CVSS vector metric that explains the vector value. This could be easily automated with linter.
  2. nickleali commented on Jul 9, 2026

    @nickleali

    Relating as well to understanding and application of the CVSS standard, the CVSS SIG remains available to help in both clarifying CVSS standards documentation to improve quality of analysis prior to entry in CVE databases, as well as assisting with validation of and improvement of data already in the CVE database.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions