CypherCon 2026
WTF is going on with CVE?
Josh Bressers
Abstract:
If you rely on vulnerability data (and we all do), it’s been an absolutely bananas couple of years. NVD melted down, CVE lost funding, but then didn’t, or something, nobody really knows. CVSS sucks and EPSS is cool, sometimes KEV is OK, nobody knows what SSVC is. It seems like nothing makes sense anymore and it’s impossible to keep track of what’s happening.
Nothing ever made sense, it just wasn’t as obvious before. Now that the reality of our vulnerability mess is public, is there any hope? Spoiler: Yes, yes there is.
In this talk, let’s first explain how we got into this mess. It’s a bizarre story that sounds like something a child made up when it’s told out loud. Then, and more importantly, what can we do? If CVE is in trouble, and NVD is broken, where can we get our vulnerability data? Many of us need vulnerability data to get our jobs done, we’re well past the point we can ignore it and pretend it’ll all be fine.
There are some public projects that are positioning themselves as useful replacements. The EU has a vulnerability database in the works. Luxembourg, the country, has something called GCVE. GitHub has a phenomenal database (it’s probably the best). There’s a community effort with OWASP called GVIP. There will probably be even more efforts by the time Cyphercon begins. But nothing is a drop in replacement for CVE and NVD. Once we understand what these sources do well, we can use them to solve our problems.
This talk will contain intrigue, stupidity, and hope. Probably not in that order. And not in equal amounts.

Josh Bressers
VP of Security, Anchore & Hacker History
Josh Bressers is the Vice President of Security at Anchore, where he guides security features and serves as a public evangelist on topics like compliance, open source, and software supply chain security. With a career spanning over 20 years, Josh has a deep-rooted history in the open-source security community. Prior to Anchore, he built the product security team at Elastic and was an early member of the Red Hat Security Response Team, where he later founded the Product Security Team. Josh is a passionate contributor to the security community, he hosts both the “Open Source Security Podcast” and the “Hacker History Podcast.” Josh is an active member of the OpenSSF where he also co-leads the SBOM Everywhere project.