Hi everyone! I am submitting a talk proposal for the July 30th "CVE in an Era of AI-Enabled Vulnerability Discovery" virtual conference.
Format: Individual talk (can compress to a lightning talk if the agenda requires)
Theme alignment: Evidence of how the CVE system strains against OSS maintainer realities, how AI-enabled vulnerability discovery is accelerating that strain toward a breaking point, and what we are working on to reduce OSS maintainer burden.
Speaker: Jessy Ayala, University of California, Irvine
Abstract
The CVE system was designed for software vendors with dedicated security teams, but open-source maintainers—volunteer-driven, resource-constrained, and often without formal security training—are increasingly expected to engage with it (our previous research published at IEEE S&P and USENIX Security further emphasizes similar challenges around security tooling usability and maintainer burden). Our recent work, currently under review, systematically ranked CVE-related challenges from the OSS maintainer perspective: we found that “producing fixes” is the topmost challenge, “lacking project context” is the top usability barrier, and “CVSS complexity” is the most-listed complaint—all of which AI may assist with; however, no one mentioned using AI for CVE-related workflows.
On the other hand, AI-generated ("slop") bug bounty reports are now amplifying every one of these challenges. The cURL project shut down its bug bounty program in January 2026 after validity rates fell below 5%. HackerOne reports submissions doubled year-over-year in April 2026. Google's OSS VRP publicly warned against AI-generated submissions. These reports increase noise, inflate severity without project context, reference hallucinated files and functions, and multiply the triage burden on maintainers already stretched thin. AI can help tackle such challenges.
In response, we are developing MINT (Maintainer-INformed Triage framework), a pipeline that cross-checks vulnerability reports against the target repository, preventing such reports from entering the CVE Lifecycle to (1) reduce maintainer burden and (2) prevent the propagation of low-quality and slop reports early on. MINT verifies whether referenced artifacts exist, assesses report quality and actionability, detects severity inflation, and produces a concise maintainer-facing triage brief. We are designing iteratively with community input to ensure MINT serves real-world triage workflows across the CVE ecosystem, and we need your help getting it right:
- We are soliciting real-world AI-slop submissions from OSS maintainers to build a large dataset of OSS reports as experienced in the wild. So far, we have been gathering as many bug bounty reports as possible from OSS bug bounty programs and publicly disclosed AI slop, e.g., from cURL, to build a corpus of both legitimate and low-quality reports, including valid AI-generated reports—we want it all.
- We are also looking for feedback on MINT's design and usefulness, e.g., Does the triage output match real decision-making? Could platforms deploy this as a quality gate? We need security folks to help us finalize MINT's design and in the near future, maintainers to help us evaluate the usefulness of MINT’s output.
If you are interested in contributing to the two points above to help advance our research, please shoot me an email. Thank you!
Takeaway
As AI-enabled vulnerability discovery scales beyond human triage capacity, the CVE ecosystem must consider where in the CVE Record Lifecycle to insert quality gates; doing so early is a way the community can adopt without requiring major changes to the CVE standard itself.
Contact
Hi everyone! I am submitting a talk proposal for the July 30th "CVE in an Era of AI-Enabled Vulnerability Discovery" virtual conference.
Format: Individual talk (can compress to a lightning talk if the agenda requires)
Theme alignment: Evidence of how the CVE system strains against OSS maintainer realities, how AI-enabled vulnerability discovery is accelerating that strain toward a breaking point, and what we are working on to reduce OSS maintainer burden.
Speaker: Jessy Ayala, University of California, Irvine
Abstract
The CVE system was designed for software vendors with dedicated security teams, but open-source maintainers—volunteer-driven, resource-constrained, and often without formal security training—are increasingly expected to engage with it (our previous research published at IEEE S&P and USENIX Security further emphasizes similar challenges around security tooling usability and maintainer burden). Our recent work, currently under review, systematically ranked CVE-related challenges from the OSS maintainer perspective: we found that “producing fixes” is the topmost challenge, “lacking project context” is the top usability barrier, and “CVSS complexity” is the most-listed complaint—all of which AI may assist with; however, no one mentioned using AI for CVE-related workflows.
On the other hand, AI-generated ("slop") bug bounty reports are now amplifying every one of these challenges. The cURL project shut down its bug bounty program in January 2026 after validity rates fell below 5%. HackerOne reports submissions doubled year-over-year in April 2026. Google's OSS VRP publicly warned against AI-generated submissions. These reports increase noise, inflate severity without project context, reference hallucinated files and functions, and multiply the triage burden on maintainers already stretched thin. AI can help tackle such challenges.
In response, we are developing MINT (Maintainer-INformed Triage framework), a pipeline that cross-checks vulnerability reports against the target repository, preventing such reports from entering the CVE Lifecycle to (1) reduce maintainer burden and (2) prevent the propagation of low-quality and slop reports early on. MINT verifies whether referenced artifacts exist, assesses report quality and actionability, detects severity inflation, and produces a concise maintainer-facing triage brief. We are designing iteratively with community input to ensure MINT serves real-world triage workflows across the CVE ecosystem, and we need your help getting it right:
If you are interested in contributing to the two points above to help advance our research, please shoot me an email. Thank you!
Takeaway
As AI-enabled vulnerability discovery scales beyond human triage capacity, the CVE ecosystem must consider where in the CVE Record Lifecycle to insert quality gates; doing so early is a way the community can adopt without requiring major changes to the CVE standard itself.
Contact