Skip to main content
ChainguardRecognition

Chainguard Named a CVE Numbering Authority, Advancing Open Source Vulnerability Disclosure

What happened

Chainguard has been authorized by the Common Vulnerabilities and Exposures (CVE) Program as a CVE Numbering Authority (CNA), allowing it to assign CVE identifiers for certain open source vulnerabilities.

Source

Article excerpt

Highlighted: the sentence this signal was extracted from

Authorization enables Chainguard to assign CVEs for qualifying open source vulnerabilities processed through Athena, helping protect open source software from AI attacks NEW YORK, Sept. 22, 2026 /PRNewswire/ -- Chainguard , the trusted source for open source, today announced that it has been authorized by the Common Vulnerabilities and Exposures (CVE ®) Program as a CVE Numbering Authority (CNA) . The mission of the CVE Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. As a CNA, Chainguard can assign CVE identifiers and publish CVE Records for qualifying vulnerabilities. The authorization is scoped to include open source vulnerabilities processed through the Athena coalition, when upstream maintainers have already fixed the flaw without an identifier, no maintainer remains to assign one, or no more specific CNA covers the project. This milestone underscores Chainguard's deep commitment to transparent, coordinated vulnerability disclosure and protecting open source software from AI attacks. Frontier AI models are surfacing latent vulnerabilities in widely used open source software that traditional security tools and years of expert review failed to detect. As AI compresses the time between discovery and exploitation, vulnerabilities without CVE identifiers may remain invisible to the scanners, databases, and compliance systems...

Keep reading with a free account

The rest of this article, and every signal for Chainguard, is in your free account.

Extracted by Autobound

From the Signal API record
Event
Recognition

What this signalsAnalyst or press recognition often comes during a period of growth.

Recognition
CVE Numbering Authority (CNA)
Takes effect
Sep 22, 2026
Location
New York, New York, United States

More recognition signals at other companies

The full record

From the Signal API record

Extraction

Confidence
95%
Detected
Sep 22, 2026
signal_type
news
signal_subtype
recognized_as

Use this data

Get every recognition signal for Chainguard and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Chainguard this week?”

  2. Send it to your own tools

    The Signal API returns recognition signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/6e8f0688-eeb5-3349-a53c-d0903c38e617 returns this record as JSON. POST /v1/companies/enrich returns every signal for chainguard.dev.

{
  "signal_id": "6e8f0688-eeb5-3349-a53c-d0903c38e617",
  "signal_type": "news",
  "signal_subtype": "recognized_as",
  "detected_at": "2026-09-22T21:22:00+00:00",
  "company": {
    "name": "Chainguard",
    "domain": "chainguard.dev"
  },
  "data": {
    "url": "https://www.prnewswire.com/news-releases/chainguard-named-a-cve-numbering-authority-advancing-open-source-vulnerability-disclosure-302886770.html",
    "title": "Chainguard Named a CVE Numbering Authority, Advancing Open Source Vulnerability Disclosure",
    "excerpt": "Authorization enables Chainguard to assign CVEs for qualifying open source vulnerabilities processed through Athena, helping protect open source software from AI attacks NEW YORK , Sept. 22, 2026 /PRNewswire/ -- Chainguard , the trusted source for open source, today announced that it has been authorized by the Common Vulnerabilities and Exposures (CVE ®) Program as a CVE Numbering Authority (CNA) . The mission of the CVE Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. As a CNA, Chainguard can assign CVE identifiers and publish CVE Records for qualifying vulnerabilities. The authorization is scoped to include open source vulnerabilities processed through the Athena coalition, when upstream maintainers have already fixed the flaw without an identifier, no maintainer remains to assign one, or no more specific CNA covers the project. This milestone underscores Chainguard's deep commitment to transparent, coordinated vulnerability disclosure and protecting open source software from AI attacks. Frontier AI models are surfacing latent vulnerabilities in widely used open source software that traditional security tools and years of expert review failed to detect. As AI compresses the time between discovery and exploitation, vulnerabilities without CVE identifiers may remain invisible to the scanners, databases, and compliance systems...",
    "summary": "Chainguard has been authorized by the Common Vulnerabilities and Exposures (CVE) Program as a CVE Numbering Authority (CNA), allowing it to assign CVE identifiers for certain open source vulnerabilities.",
    "location": "NEW YORK",
    "planning": false,
    "image_url": "https://mmx.prnewswire.com/media/MS684620/Chainguard-Logo.jpg?id=OA2965138&p=facebook",
    "confidence": 0.95,
    "recognition": "CVE Numbering Authority (CNA)",
    "published_at": "2026-09-22T21:22:00Z",
    "location_data": [
      {
        "city": "New York",
        "state": "New York",
        "region": "Northern America",
        "country": "United States",
        "continent": "Americas",
        "fuzzy_match": false
      }
    ],
    "effective_date": "2026-09-22",
    "article_sentence": "Chainguard , the trusted source for open source, today announced that it has been authorized by the Common Vulnerabilities and Exposures (CVE ®) Program as a CVE Numbering Authority (CNA) ."
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.