Understanding the Vulnerability Scoring Issues
In a recent analysis, Sonatype disclosed that the Common Vulnerabilities and Exposures (CVE) system is struggling to adapt to the rapidly evolving landscape of software development. The report titled Trust Issues: The CVE Crisis indicates that a vast majority of the most common vulnerabilities lack proper severity scores. This analysis, part of a study involving 1,552 open source vulnerabilities disclosed in 2025, reveals that approximately 64% of these vulnerabilities are unscored according to the National Vulnerability Database (NVD).
The Study's Key Findings
Sonatype's Security Research Team found several critical shortcomings in the CVE system. These findings, drawn from their extensive research, paint a troubling picture of the reliability and effectiveness of current vulnerability management practices.
Coverage Issues
One of the starkest revelations from the report is the plummeting coverage of the CVE system. The analysis showed that only 36% of open-source CVEs possess an assigned CVSS score from the NVD. This severely limits security teams’ ability to prioritize vulnerabilities effectively, with nearly half of the unscored vulnerabilities identified as being in the Critical or High-risk categories upon Sonatype’s review.
Concerns Over Accuracy
Accuracy in vulnerability assessments is paramount for organizations striving to maintain robust security postures. Unfortunately, out of the CVEs that did receive severity scores, less than 20% had correct ratings. An alarming 62% of scores inaccurately overstated the severity of vulnerabilities while 34% understated it. This includes the identification of an overwhelming number of false positives and negatives, which means resources are wasted and genuine threats may go unnoticed.
Timeliness of Vulnerability Reporting
The report also underscored issues related to the timeliness of reporting vulnerabilities. In 2025, there was an average delay exceeding six weeks from the time a vulnerability was disclosed to when it was scored by the NVD, with some cases taking up to 50 weeks. Such delays are critical because they can render the information outdated and less useful in the fast-paced world of software development and cyber defense.
Moving Toward Real-Time Intelligence
According to Brian Fox, CTO and Co-founder of Sonatype, the traditional CVE program cannot handle the reality of modern, component-based software development, especially with the increasing integration of AI technologies. He emphasizes that the shift should be toward real-time intelligence that reflects the current state of deployments instead of static historical data.
Introducing Nexus One
Sonatype is already pioneering this shift with Nexus One, its AI-native DevSecOps platform that integrates open source intelligence, governance, and automation in one comprehensive solution. Leveraging over 15 years of significant open source knowledge and advanced machine learning techniques, Nexus One can provide insights ten times faster than traditional systems and enable organizations to mitigate risks 30% quicker on average.
Conclusion and Forward Steps
The findings presented in Sonatype's report emphasize the urgent need for innovation in how organizations manage cybersecurity risks related to vulnerabilities. As noted by Bhagwat Swaroop, CEO of Sonatype, the challenges faced by traditional CVE systems require a new approach that emphasizes real-time visibility and automated governance to help organizations maintain a competitive edge while developing secure software solutions.
Frequently Asked Questions
What is the main focus of Sonatype's report?
Sonatype's report focuses on the critical shortcomings of the CVE system, revealing that a significant portion of vulnerabilities lack proper severity scores, impacting software security management.
How many vulnerabilities were analyzed in the Sonatype study?
The study analyzed 1,552 open source vulnerabilities disclosed in 2025.
What percentage of open-source CVEs have assigned severity scores?
Only 36% of open-source CVEs had a CVSS score assigned by the National Vulnerability Database.
What role does Nexus One play in addressing these issues?
Nexus One integrates intelligence and automation to provide real-time insights, aiming to significantly reduce risk mitigation times and improve software security.
Why is timeliness a concern in reporting vulnerabilities?
Delays of several weeks in scoring vulnerabilities can lead to outdated information, which is detrimental in the fast-paced environment of software development and cybersecurity.