Demystifying the CVE Ecosystem: Community-Perceived Impacts and Problems
Yiliang Zhao, Hengzhi Ye, Minghui Zhou, Huaimin Wang
Abstract
The Common Vulnerabilities and Exposures (CVE) system plays a critical role in global cybersecurity by standardizing the identification and cataloging of software and hardware vulnerabilities. However, recent high-profile incidents highlight the potential pitfall of the system, indicating the space for improvement. Despite significant interests in and substantial studies on CVE system, there is a lack of understanding to what extent the participants are impacted, and what problems are exactly in the CVE ecosystem. To bridge the knowledge gap, we extensively collect blog posts, community discussions, and editorial articles from various sources, including Reddit, LWN.net, and GitHub, and employ a thematic analysis approach to identify the perceived adverse impact on participants as well as the inherent problems within the CVE ecosystem. Then we conducted a community survey with 77 participants for verification. The results unveil the impacts on various participants within the prevailing CVE ecosystem and for the first time comprehensively trace and elucidate the problems that may cause these impacts. Based on the findings and survey results, we propose a series of implications to mitigate existing problems within the CVE ecosystem, aiming to enhance its efficiency and health.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 4422f524-a15c-4a8f-bb43-3549727cf098Related papers
- Confusing Value with Enumeration: Studying the Use of CVEs in AcademiaMoritz Schloegel, Daniel Klischies, Simon Koch, David Klein et al.USENIX Security 2025
- Shedding Light on CVSS Scoring Inconsistencies: A User-Centric Study on Evaluating Widespread Security VulnerabilitiesJulia Wunder, Andreas Kurtz, Christian Eichenmüller, Freya Gassmann et al.S&P 2024 · 25 citations
- A Grounded Theory Based Approach to Characterize Software Attack SurfacesSara Moshtari, Ahmet Okutan, Mehdi MirakhorliICSE 2022 · 7 citations
- A Mixed-Methods Study of Open-Source Software Maintainers On Vulnerability Management and Platform Security FeaturesJessy Ayala, Yu-Jye Tung, Joshua GarciaUSENIX Security 2025
- Between Risk, Recognition, and Necessity: How Open-Source Project Maintainers Perceive and Navigate CVEs Through Reporting and Resolving VulnerabilitiesJessy Ayala, Steven Ngo, Joshua GarciaCCS 2026
