In section Releases

Chainguard Gains Authority to Issue CVEs for Open Source Security

Chainguard has secured designation as a CVE Numbering Authority, granting the firm power to assign official identifiers to open source vulnerabilities. The move aims to close critical security gaps exposed by AI-driven discovery, ensuring that flaws identified through the company’s Athena coalition are cataloged within the industry-standard CVE system.

Chainguard Gains Authority to Issue CVEs for Open Source Security

This authorization enables Chainguard to publish CVE records for vulnerabilities that lack identifiers, particularly when upstream maintainers have already deployed fixes or when no specific authority covers a project. By bridging this gap, the company seeks to prevent security threats from remaining invisible to automated scanners and compliance databases that rely on these identifiers to track risk.

Quincy Castro, Chief Information Security Officer at Chainguard, noted that AI-driven zero-day discovery is currently overwhelming traditional disclosure methods. The designation allows the firm to communicate vulnerability data in a standardized format, helping organizations prioritize remediation efforts. The Athena coalition—which includes partners like Akamai, BNY, Cisco, and JPMorganChase—will now use this authority to validate vulnerabilities and coordinate durable upstream fixes alongside the Akrites project. Chainguard’s records will continue to defer to primary project-specific authorities whenever they are available.

Share:on TelegramXFacebook

Subscribe to our newsletter

Once a week — the best stories from our editors, no ads or push notifications. Delivered Sunday morning.

Comments (0)

Leave a comment

No comments yet. Be the first!