AI slop pollutes the CVE pipeline with fake vulns
A batch of 55 supposedly critical and high-severity CVEs published in the US National Vulnerability Database last week turned out to be fabricated, according to security researchers, exposing serious gaps in how vulnerability reports are verified before entering widely used databases. Software supply chain firm JFrog found that six SQLite vulnerabilities, submitted via an obscure GitHub repository and enriched by CISA, described no reproducible flaws at all, with one alleged bug relying on a function that doesn't exist in the affected version and another citing unrelated source code. JFrog's testing suggested the reports were likely AI-generated, and the incident highlights how the CVE system's honour-based trust model is being exploited or undermined by AI-produced "slop."
Of the fake reports, six targeted SQLite with CVSS scores ranging from 7.5 to 9.8, while the remaining 49 falsely claimed flaws in the libraw image library and the ESP32-audioI2S Arduino audio decoder; only one contained a genuine bug amid fabricated metadata. MITRE has since rejected the entire batch, but the case underscores a structural weakness: CVE-assigning bodies (CNAs) typically cannot independently verify reports for code they don't produce themselves. This problem is compounded by NIST's ongoing backlog crisis, which had grown to over 27,000 unprocessed CVEs by the end of 2025, according to a May 2026 Commerce Department inspector general report that also criticised the agency's poor strategic planning in tackling the issue.
- 55 fake, likely AI-generated CVEs slipped into the NVD before MITRE rejected them
- JFrog found SQLite bugs citing non-existent functions and unrelated code
- NIST's 27,000+ CVE backlog leaves no reliable verification checkpoint