CVE system incentives are broken and getting worse
A thread titled 'A CVE Dispute' digs into how the incentive structure around Common Vulnerabilities and Exposures has degraded. The key observation: having a CVE against an important project like curl carries professional cachet and can be leveraged for job hunting, so people are filing CVEs for marginal or contested vulnerabilities to put them on a resume. One commenter jokes it's 'someone really wanting to put this on their CV.'
The broader problem is that CVEs were designed to be a neutral public record of real security issues. When they become resume items, the signal degrades. Maintainers of popular open source projects spend real time responding to and disputing low-quality CVE filings, which is a tax on the people keeping critical infrastructure running.
This connects to the earlier infrastructure security threads and the IoT regulation Ask HN. The systems designed to surface and track security issues are themselves being gamed, which makes the actual security posture of software harder to assess.
So what?
If you maintain open source software or build on top of packages that get CVEs filed against them, expect to spend more time on triage of low-quality filings. For founders building security products, there is a real gap in tooling that helps distinguish genuine CVEs from reputation-seeking noise, and that gap is growing.