US gov’t funding for CVE database ends April 16th, MITRE Corp says


The US Department of Homeland Security’s funding to maintain the critical Common Vulnerabilities and Exposures (CVE) database, used by cybersecurity professionals worldwide, will end on Wednesday, April 16th.

That’s according to the defense and research-focused nonprofit MITRE Corporation, responsible for maintaining the critical database of cyber vulnerabilities.

The Common Vulnerabilities and Exposures (CVE) database aims to identify, define, and catalog publicly disclosed cyber weaknesses, enabling IT administrators to quickly flag and triage the myriad different bugs and hacks discovered daily.

ADVERTISEMENT

The common numbering scheme, severity scale, and detailed descriptions allow quick communication of highly technical information across organizations and around the world.

MITRE said in an email that the funding "will expire" on Wednesday. The Cybersecurity and Infrastructure Security Agency (CISA), whose parent agency funds the contract, confirmed the contract was ending and said "we are urgently working to mitigate impact and to maintain CVE services on which global stakeholders rely."

adi Neilc Stefanie Konstancija Gasaityte profile
Stay informed and get our latest stories on Google News

Reuters couldn't establish the reason for the contract's lapse, but CISA is, like the rest of the federal government, undergoing a radical downsizing driven in part by tech tycoon Elon Musk's U.S. DOGE Service. A spokesperson for DOGE didn't immediately reply to an email.

Cyber defenders said they were aghast at the news of the program's lapse. One compared it to suddenly deleting all dictionaries.

"We'd lose the language and lingo we use to address problems in cybersecurity," said John Hammond, the principal security researcher at managed security company Huntress. He said he swore out loud when he heard the news. "I really can't help but think this is just going to hurt."

Organizations around the world lean on the CVE database to triage which vulnerabilities in their digital products need immediate attention versus which ones can be put off, allowing them to manage when and how to update software or patch security holes.

Pulling the plug on the database would cause "an immediate cascading effect that will impact vulnerability management on a global scale," said Brian Martin, a historian of computer vulnerabilities.

ADVERTISEMENT

He said that Computer Emergency Response Teams - the digital first responders known as CERTs - would "no longer have that source of free vulnerability intelligence" and that "every company in the world" that relied on the database for vulnerability intelligence "is going to experience swift and sharp pains to their vulnerability management program."