Skip to content

Some issues with data degradation between upstream, CVE and NVD, then Gihub, OSV and Gitlab #2409

Description

@pombredanne

Some ASF projects are seeing their CVE records appearing mangled in GitHub Advisories, but this is only a symptom of a deeper problem and not specific to the ASF. Thanks for @ppkarwasz for the details

An example is CVE-2026-50628 (disclosed on June 12th), which has a CVSS score of 9.8, and is only present in that PURL pkg:maven/org.apache.cxf/cxf-rt-rs-security-oauth2 and not in the whole CXF codebase.

Here are some background:

Then OSV and GitLab

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions