The world’s most widely used vulnerability index, the Common Vulnerabilities and Exposures (CVE) program, is struggling with widespread inaccuracies and delays, according to new research from Sonatype, resulting in tens of thousands of false reports and leaving AI development pipelines exposed.
After analysing more than 1,500 open source vulnerabilities disclosed this year, the DevSecOps platform’s latest report, Trust Issues: The CVE Crisis, found that nearly two-thirds (64%) lacked severity scores assigned by the National Vulnerability Database (NVD).
According to Sonatype, of the CVEs that were scored, fewer than one in five severity ratings were correct, with 62% of NVD scores overstating severity, and more than a third (34%) understating the threat.
Added to that, the firm found that nearly half of all unscored vulnerabilities should have been classed as either Critical or High, leading Sonatype to argue that coverage of emerging cyber threats is at risk of collapse.
Those issues are being exacerbated by disclosure delays, with 2025 witnessing a mean delay of more than six weeks between disclosure and NVD scoring, and some advisories taking up to 50 weeks.
Sonatype said that this is evidence that the CVE/NVD pipeline is not keeping pace with today’s exploit timelines and threatens to turn official data into an “operational bottleneck”.
Put together, the cracks in the CVE system are putting businesses at enormous risk, as without access to timely and accurate data, security professionals are unable to triage cases, effectively forcing them to gamble on incomplete information.
Illustrating the point, Sonatype uncovered 19,945 false positives and a staggering 156,474 false negatives across CVE records, wasting developer time and obscuring real threats.
“The CVE program was never built for the scale and speed of modern, component-based software development,” said Brian Fox, CTO and co-founder of Sonatype.
“Vulnerability intelligence must shift from indexing what someone assigned yesterday, to delivering real-time insight into what’s actually running in your environment. CVE remains a shared language — but it can’t be the full story anymore.”
Recommended reading
- Less than Half of All Exploitable Vulnerabilities Get Fixed
- Commercial Codebases Leave Gaping Vulnerabilities
- High Risk Sectors Have the Most Critical Vulnerabilities
That is especially true as AI-centric software development becomes more commonplace, said the firm, with LLMs, agentic agents and vibe coding platforms at risk of “inheriting blind spots” when vacuuming in immense amounts of foundational data like CVSS scores and false negatives, leading to AI that might underestimate real risks.
With AI taking a growing role in most businesses’ defences, these gaps in vulnerability data could well fuel unsafe assumptions at scale, adding to security debt instead of easing it.
“Traditional systems can’t keep up with the scale and sophistication of open source risk associated with genAI and agentic AI development,” said Bhagwat Swaroop, CEO of Sonatype.
Don’t Miss Scotland’s Largest Tech Event of the Year – DIGIT Expo: 27th November
50 Speakers – 40 Exhibitors – 2000 Delegates
Don’t miss DIGIT Expo, Scotland’s largest annual tech gathering, taking place at the EICC in Edinburgh on 27th November. We have a stacked conference agenda with 5 Stages of leading edge content, including presenters from Microsoft, Amazon, Spotify, Morgan Stanley, Alibaba, and NVIDIA…
Register now at: https://digit-expo.com/





