Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <50634ab6-292f-4821-9254-108dea918cef@hauke-m.de>
Date: Tue, 9 Jun 2026 22:32:10 +0200
From: Hauke Mehrtens <hauke@...ke-m.de>
To: oss-security@...ts.openwall.com
Cc: David Bauer <mail@...id-bauer.net>
Subject: How to request CVE numbers?

Hi,

How to get a CVE number as a community driven open source project 
(OpenWrt)? We do not have a security department or a big company backing us.

Multiple security problems were reported to OpenWrt in the last few 
months. We want to assign CVE numbers to these problems, but have 
problems requesting numbers.

We contacted mitre in the past, but did not got a response within 2 
weeks. Using github security advisories worked fine 2 months ago, we got 
a CVE number in some days. Currently this does not work any more, we are 
already waiting for 1 week.

How to get a CVE number?

We (OpenWrt) are a community driven open source project and got multiple 
reports from individuals and organizations like OpenAI.

We requested multiple CVE Numbers on github for this project: 
https://github.com/openwrt/odhcpd

Hauke

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.