Chainguard Named a CVE Numbering Authority, Advancing Open Source Vulnerability Disclosure
Article excerpt
Highlighted: the sentence this signal was extracted from
Authorization enables Chainguard to assign CVEs for qualifying open source vulnerabilities processed through Athena, helping protect open source software from AI attacks NEW YORK, Sept. 22, 2026 /PRNewswire/ -- Chainguard , the trusted source for open source, today announced that it has been authorized by the Common Vulnerabilities and Exposures (CVE ®) Program as a CVE Numbering Authority (CNA) . The mission of the CVE Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. As a CNA, Chainguard can assign CVE identifiers and publish CVE Records for qualifying vulnerabilities. The authorization is scoped to include open source vulnerabilities processed through the Athena coalition, when upstream maintainers have already fixed the flaw without an identifier, no maintainer remains to assign one, or no more specific CNA covers the project. This milestone underscores Chainguard's deep commitment to transparent, coordinated vulnerability disclosure and protecting open source software from AI attacks. Frontier AI models are surfacing latent vulnerabilities in widely used open source software that traditional security tools and years of expert review failed to detect. As AI compresses the time between discovery and exploitation, vulnerabilities without CVE identifiers may remain invisible to the scanners, databases, and compliance systems...
Keep reading with a free account
The rest of this article, and every signal for Chainguard, is in your free account.
