AI slop pollutes the CVE pipeline with fake vulns
What happened
Researchers and JFrog flagged a set of publicly posted CVEs that were technically bogus and likely AI-generated, and those advisories flowed into databases and scanner outputs that enterprises rely on. The incident is operationally real because the CVE ingestion process accepts submitter claims without universal proof-of-concept, so buyers can receive and act on false alerts. Watch whether CVE authorities and major scanner vendors tighten submission validation or whether enterprises implement source filtering
Why the category manager should care
Do not accept scanner or feed outputs as authoritative without supplier provenance; make reproducible proof a contractual gating factor for emergency actions
Key facts
- Six supposed SQLite CVEs in one batch were judged bogus during testing
- A separate batch contained 49 advisories in the same obscure repository that lacked reproduci