The CVE program itself is an unauthenticated remote DoS vulnerability
The CVE program itself is an unauthenticated remote DoS vulnerability
Posted Aug 3, 2026 15:28 UTC (Mon) by neverpanic (subscriber, #99747)In reply to: The CVE program itself is an unauthenticated remote DoS vulnerability by geofft
Parent article: SQLite Critical CVEs or LLM Slop? (JFrog blog)
This, so much this. Way too many consumers don't do anything beyond "this has a 9.8 CVSS score by NiSt VulNriCHmeNT, plzfix11!!!" these days, not realizing that these scores make some very conservative assumptions (for lack of better knowledge of the actual target system) that mostly don't hold on a modern Linux these days, e.g., the absence of stack canaries, ASLR, or other standard hardening measures.
If the endless wave of CVEs we are seeing leads to consumers (read: companies) adopting better practices in what's actually worth fixing, that would be a very good outcome.
Unfortunately I doubt it'll happen, and instead we'll just see everybody rush to deploy quicker.
