News
Insight

Vulnerabilities: MITRE runs out of funding for CVE

A cornerstone resource for identifying and tracking known vulnerabilities is at risk as MITRE's contract to develop and maintain the CVE programme expires today. Without further funding, new vulnerabilities cannot be assigned CVE numbers, making coordination between vendors, security analysts and defence systems more difficult.

Update 2025-04-17: The programme's principal sponsor, the Cybersecurity and Infrastructure Security Agency (CISA), has secured funding — for eleven months, according to reports. But the crisis is far from over.

News that the funding had run out broke less than two days before a threatened shutdown. Within 24 hours, the EU launched its long-in-development alternative, EUVD. That points to a global lack of trust, notes Brian Martin, former member of the CVE Editorial Board, now with the company Flashpoint, speaking at a seminar on Thursday.

— This isn't the first, but it is a major blow to the trust the world previously placed in the US to handle this.

Managing that trust will be a challenge for the CVE programme in 2025.

In an attempt to strengthen independence, members of the CVE board established a foundation on 16 April, the CVE Foundation. Letting governments run the task instead of CVE creates political dependencies. Letting large companies such as Google, Microsoft, Apple or Amazon run it makes it hard to trust that the information is impartial. Letting non-profit organisations run it makes it hard to know who is a genuine expert. If CVE disappears, the EU may therefore be the least-bad option to take over, according to Brian Martin. But most of the vulnerabilities in the EU's database still originate from CVE.

— It will take another party two to five years to catch up to where CVE has got to, he says, noting that later this year the world could face a period without any comprehensive authority in this area.

That makes it essential to have tools in place that don't depend on CVE as their source. Many will claim to fill that role, but Brian Martin doesn't see any good coming from CVE shutting down.

— It wouldn't help anyone. This came as a shock to many of us. A reasonable approach would have been to announce a four-year wind-down period — not two days, he says.

The EU's cybersecurity agency ENISA has since 2024 been an authorised CVE Numbering Authority for vulnerabilities. ENISA can assign CVE IDs to vulnerabilities discovered by, or reported to, the EU's network of Computer Security Incident Response Teams (CSIRT), such as Sweden's CERT-SE.

Since 2016, ENISA has been developing its own vulnerability database, EUVD, in line with the NIS2 Directive. EUVD aggregates vulnerabilities from various sources, including CSIRTs, vendors and existing databases — but ENISA is not planning a comprehensive database of all vulnerabilities, as was previously proposed under the Cyber Resilience Act.

MITRE is a non-profit organisation in the US that runs several research centres for US federal agencies, including defence, intelligence, healthcare and cybersecurity. Funding comes from the US Department of Defense, the Department of Homeland Security and other agencies.

The funding issue stems from delays in federal budget decisions, a possible restructuring of responsibility for the CVE programme, and consideration of moving operations to other parties. The consequences could include greater fragmentation across the industry, problems for tools, databases and feeds that depend on CVE, and weaker global coordination of vulnerability management.

A new administration and a potentially less supportive political climate in Congress have created uncertainty for CISA's funding as well.

CVE names, NVD enriches. The National Institute of Standards and Technology (NIST) maintains a vulnerability database, the National Vulnerability Database (NVD). A vulnerability is assigned a CVE ID by MITRE or another numbering authority (CNA). NVD automatically ingests CVE entries and enriches them with technical analysis, scoring (CVSS), references, remediation guidance, product-specific information (CPE), links to exploits and patches, exportable as JSON/XML.

NVD: During 2024, the backlog of vulnerabilities awaiting processing — those with status "Awaiting Analysis" — has surged.

NVD: During 2025, the number of vulnerabilities with work in progress, "Undergoing Analysis", is skyrocketing. In practice, the work doesn't look like it will get finished. Compilation: Flashpoint, one of several companies that analyse vulnerabilities in parallel with the government-run NIST and draw on the CVE programme.

Coordinated, fast, accurate and relevant data is essential for responding to vulnerabilities effectively. Graphic: Seclight.

Read more:

Krebs on Security

The Verge

The Record

Federal News Network


Seclight — the right security, in the right order.

+46 8 94 55 99 info@seclight.com