CVE 基金会启动,以保障 CVE 计划的未来
CVE Foundation

原始链接: https://www.thecvefoundation.org/home

CVE 基金会于2025年4月16日启动,旨在保障通用漏洞和披露(CVE)计划的未来。CVE计划是全球网络安全领域25年来至关重要的组成部分。此举是在MITRE宣布美国政府将不续签管理CVE计划的合同之后做出的,该计划历来由政府资助。 对该计划在单一政府赞助商下的可持续性和中立性方面的担忧,促使CVE董事会成员联盟成立了非营利性CVE基金会。该基金会旨在确保CVE计划的长期生存能力、稳定性和独立性。 基金会官员肯特·兰德菲尔德强调了CVE标识符和数据对全球网络安全专业人员的关键作用,并警告了其缺失的后果。CVE基金会旨在消除漏洞管理中的单点故障,并促进一个社区驱动、全球信任的倡议。有关结构、过渡和社区参与的更多详细信息将很快发布。垂询请联系[email protected]

一篇Hacker News帖子讨论了CVE基金会的启动,旨在确保CVE项目的未来。评论区对此举表示怀疑。用户指出CVE官网上缺乏官方公告,以及最近才注册的域名,这与所谓的为期一年的规划相矛盾。人们对该基金会的合法性和其是否真正代表了一个统一的解决方案表示担忧。一位评论者质疑一家美国非营利组织的适宜性,并指出可能存在的政府影响,并更倾向于一个更独立的实体。总体情绪是谨慎观察和对该基金会实际影响和独立性的不确定性。

原文

FOR IMMEDIATE RELEASE

April 16, 2025

CVE Foundation Launched to Secure the Future of the CVE Program

[Bremerton, Washington] – The CVE Foundation has been formally established to ensure the long-term viability, stability, and independence of the Common Vulnerabilities and Exposures (CVE) Program, a critical pillar of the global cybersecurity infrastructure for 25 years.

Since its inception, the CVE Program has operated as a U.S. government-funded initiative, with oversight and management provided under contract. While this structure has supported the program’s growth, it has also raised longstanding concerns among members of the CVE Board about the sustainability and neutrality of a globally relied-upon resource being tied to a single government sponsor.

This concern has become urgent following an April 15, 2025 letter from MITRE notifying the CVE Board that the U.S. government does not intend to renew its contract for managing the program. While we had hoped this day would not come, we have been preparing for this possibility.

In response, a coalition of longtime, active CVE Board members have spent the past year developing a strategy to transition CVE to a dedicated, non-profit foundation. The new CVE Foundation will focus solely on continuing the mission of delivering high-quality vulnerability identification and maintaining the integrity and availability of CVE data for defenders worldwide.

“CVE, as a cornerstone of the global cybersecurity ecosystem, is too important to be vulnerable itself,” said Kent Landfield, an officer of the Foundation. “Cybersecurity professionals around the globe rely on CVE identifiers and data as part of their daily work—from security tools and advisories to threat intelligence and response. Without CVE, defenders are at a massive disadvantage against global cyber threats.”

The formation of the CVE Foundation marks a major step toward eliminating a single point of failure in the vulnerability management ecosystem and ensuring the CVE Program remains a globally trusted, community-driven initiative. For the international cybersecurity community, this move represents an opportunity to establish governance that reflects the global nature of today’s threat landscape.

Over the coming days, the Foundation will release more information about its structure, transition planning, and opportunities for involvement from the broader community.

For updates or inquiries, contact: [email protected].

联系我们 contact @ memedata.com