News

Sonatype Report Reveals Critical CVE Scoring Gaps in Security

Sonatype Report Reveals Critical CVE Scoring Gaps in Security

Understanding the Vulnerability Scoring Issues

In a recent analysis, Sonatype disclosed that the Common Vulnerabilities and Exposures (CVE) system is struggling to adapt to the rapidly evolving landscape of software development. The report titled Trust Issues: The CVE Crisis indicates that a vast majority of the most common vulnerabilities lack proper severity scores. This analysis, part of a study involving 1,552 open source vulnerabilities disclosed in 2025, reveals that approximately 64% of these vulnerabilities are unscored according to the National Vulnerability Database (NVD).

The Study's Key Findings

Sonatype's Security Research Team found several critical shortcomings in the CVE system. These findings, drawn from their extensive research, paint a troubling picture of the reliability and effectiveness of current vulnerability management practices.

Coverage Issues

One of the starkest revelations from the report is the plummeting coverage of the CVE system. The analysis showed that only 36% of open-source CVEs possess an assigned CVSS score from the NVD. This severely limits security teams’ ability to prioritize vulnerabilities effectively, with nearly half of the unscored vulnerabilities identified as being in the Critical or High-risk categories upon Sonatype’s review.

Concerns Over Accuracy

Accuracy in vulnerability assessments is paramount for organizations striving to maintain robust security postures. Unfortunately, out of the CVEs that did receive severity scores, less than 20% had correct ratings. An alarming 62% of scores inaccurately overstated the severity of vulnerabilities while 34% understated it. This includes the identification of an overwhelming number of false positives and negatives, which means resources are wasted and genuine threats may go unnoticed.

Timeliness of Vulnerability Reporting

The report also underscored issues related to the timeliness of reporting vulnerabilities. In 2025, there was an average delay exceeding six weeks from the time a vulnerability was disclosed to when it was scored by the NVD, with some cases taking up to 50 weeks. Such delays are critical because they can render the information outdated and less useful in the fast-paced world of software development and cyber defense.

Moving Toward Real-Time Intelligence

According to Brian Fox, CTO and Co-founder of Sonatype, the traditional CVE program cannot handle the reality of modern, component-based software development, especially with the increasing integration of AI technologies. He emphasizes that the shift should be toward real-time intelligence that reflects the current state of deployments instead of static historical data.

Introducing Nexus One

Sonatype is already pioneering this shift with Nexus One, its AI-native DevSecOps platform that integrates open source intelligence, governance, and automation in one comprehensive solution. Leveraging over 15 years of significant open source knowledge and advanced machine learning techniques, Nexus One can provide insights ten times faster than traditional systems and enable organizations to mitigate risks 30% quicker on average.

Conclusion and Forward Steps

The findings presented in Sonatype's report emphasize the urgent need for innovation in how organizations manage cybersecurity risks related to vulnerabilities. As noted by Bhagwat Swaroop, CEO of Sonatype, the challenges faced by traditional CVE systems require a new approach that emphasizes real-time visibility and automated governance to help organizations maintain a competitive edge while developing secure software solutions.

Frequently Asked Questions

What is the main focus of Sonatype's report?

Sonatype's report focuses on the critical shortcomings of the CVE system, revealing that a significant portion of vulnerabilities lack proper severity scores, impacting software security management.

How many vulnerabilities were analyzed in the Sonatype study?

The study analyzed 1,552 open source vulnerabilities disclosed in 2025.

What percentage of open-source CVEs have assigned severity scores?

Only 36% of open-source CVEs had a CVSS score assigned by the National Vulnerability Database.

What role does Nexus One play in addressing these issues?

Nexus One integrates intelligence and automation to provide real-time insights, aiming to significantly reduce risk mitigation times and improve software security.

Why is timeliness a concern in reporting vulnerabilities?

Delays of several weeks in scoring vulnerabilities can lead to outdated information, which is detrimental in the fast-paced environment of software development and cybersecurity.

About The Author

About Investors Hangout

Investors Hangout is a leading online stock forum for financial discussion and learning, offering a wide range of free tools and resources. It draws in traders of all levels, who exchange market knowledge, investigate trading tactics, and keep an eye on industry developments in real time. Featuring financial articles, stock message boards, quotes, charts, company profiles, and live news updates. Through cooperative learning and a wealth of informational resources, it helps users from novices creating their first portfolios to experts honing their techniques. Join Investors Hangout today: https://investorshangout.com/

The content of this article is based on factual, publicly available information and does not represent legal, financial, or investment advice. Investors Hangout does not offer financial advice, and the author is not a licensed financial advisor. Consult a qualified advisor before making any financial or investment decisions based on this article. This article should not be considered advice to purchase, sell, or hold any securities or other investments. If any of the material provided here is inaccurate, please contact us for corrections.

Top 10 Most Recent News Articles

Top 5 Most Recently Viewed Articles

Primo Brands Faces Legal Deadline Amidst Merger Controversy

Updated Category News Views 226

Understanding the Primo Brands Legal Situation Investors should be aware that Primo Brands Corporation (NYSE: PRMB) is currently facing a significant lawsuit related to its recent merger. As the January deadline approaches, many are urged to take action regarding their investments. Key Allegations Against Primo Brands The lawsuit, led by the law firm Hagens Berman, raises...

Continue Reading
Stay Hydrated This Holiday Season with Magnum Nutraceuticals

Updated Category News Views 82

Hydration Made Easy with REFRSH The holiday season is often filled with celebrations and indulgence, making it tough to maintain healthy habits. This is where Magnum Nutraceuticals' REFRSH comes into play. This on-the-go supplement aims to simplify the process of staying hydrated by providing a blend of essential nutrients that are both effective and delicious. Packed...

Continue Reading
Discover Ruko's U11MINI 4K Drone for Unmatched Summer Fun

Updated Category News Views 148

Unleash Your Summer Adventures with Ruko's U11MINI 4K Drone Ruko, known for making drones accessible and enjoyable, is promoting the outstanding U11MINI 4K Drone, a lightweight marvel that is perfect for both novices and those who love outdoor activities. This drone makes an excellent companion for summer excursions, whether you're camping, hiking, or enjoying outdoor...

Continue Reading
Birchtree Investments Plans to Expand Through New Financing

Updated Category News Views 157

Birchtree Investments Announces New Financing Plans Birchtree Investments Ltd. (CSE: BRCH), an innovative investment firm, is excited to share its plans for a proposed non-brokered private placement. This initiative is aimed at raising up to $1 million by offering common shares priced at $0.02 each. The company’s long-term objective is to strategically divest its...

Continue Reading
inKind's $450 Million Play: Revolutionizing Restaurant Financing

Updated Category News Views 241

inKind just bagged $450 million to fuel its mission of funding up to 10,000 restaurants across the U. S. in a year. This marks a significant leap for the Austin-based company that has already funneled over $600 million into more than 6,000 top eateries while delivering a whopping $175 million in dining rewards for over four million users. The latest cash influx is set to...

Continue Reading