Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

In August 2018, the House Energy and Commerce Committee criticized the Common Vulnerabilities and Exposures (CVE) program for relying on unstable contracting, lacking systematic oversight and accumulating delays in processing vulnerability submissions. The committee urged the Department of Homeland Security (DHS) to establish a dedicated annual budget line and called for reviews every two years. The dispute was about the resilience of a service used across the global security ecosystem—not simply a backlog. A 2025 contract controversy renewed questions about whether that resilience problem has been solved.

What CVE does—and what it does not do

CVE is a shared system for assigning identifiers and publishing records about publicly known software and hardware vulnerabilities. A CVE ID gives vendors, security teams and tools a common reference for discussing a particular vulnerability. It helps connect advisories, scanners, patch-management systems, incident response and asset inventories.

A CVE ID is not, by itself, a severity rating or a decision that a vulnerability is exploitable in a particular environment. Nor is CVE the same as the National Vulnerability Database (NVD). NIST operates the NVD, which adds information such as severity and affected-product data to CVE records. CVE presence alone does not establish exposure, priority or the right remediation for an organization.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • CNAs: CVE Numbering Authorities are organizations authorized to assign CVE IDs within defined scopes.
  • CNA of Last Resort: An authority that can assign IDs when no other CNA is responsible.
  • CVE Board: A stakeholder body involved in program governance.
  • NVD: A separate NIST-operated database that enriches CVE records; it is not the CVE program itself.

The CVE FAQ says CISA funds HSSEDI, a DHS-sponsored federally funded research and development center operated by MITRE, to run the program in cooperation with government, industry and academic stakeholders. CVE program FAQ

What the House committee found in 2018

In an investigation lasting more than a year, the House Energy and Commerce Committee examined the program’s contracting, oversight and operating difficulties. CyberScoop reported on August 27, 2018, that committee members sent letters to DHS and MITRE describing their concerns. The panel counted 30 awards or modifications to the CVE contract vehicle over seven years—not 30 necessarily separate contracts—and argued that repeated changes could make funding and scheduling unpredictable. CyberScoop’s August 27, 2018 report

Unstable contracting and no dedicated budget line

The committee argued that a globally relied-upon vulnerability-identification service should not depend on a sequence of short-term or piecemeal procurement actions. It asked DHS to create a dedicated annual CVE budget line and sought a more durable funding arrangement. The concern was institutional: changing contract terms or timing can make it harder to retain staff, plan modernization and sustain predictable operations.

Insufficient oversight

Lawmakers said DHS and MITRE had not reviewed the program systematically often enough. They urged formal reviews every two years, intended to surface management and performance problems before they became entrenched. The letters also asked for briefings within two weeks.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Submission delays as a management signal

Researchers had reported delays in responses to vulnerability submissions. The committee treated the backlog as a possible symptom of broader funding and management weaknesses, not merely a question of adding staff. The CyberScoop report does not provide a detailed breakdown of the backlog’s size, age or causes, so it cannot establish how much each factor contributed.

What lawmakers asked DHS and MITRE to do

  • Establish a dedicated annual DHS budget line for CVE.
  • Move away from unstable, piecemeal contracting toward a more durable funding arrangement.
  • Conduct formal DHS and MITRE reviews every two years.
  • Improve oversight of program administration and performance.
  • Address underlying causes of submission delays, rather than treating only their immediate symptoms.
  • Brief the committee on program operations and reforms.

This was congressional oversight, not a new law or enforcement order. The report describes committee letters and recommendations; it does not say Congress enacted a CVE-specific statute in response. It also notes that MITRE had undertaken reforms, while lawmakers maintained that root causes remained. The article does not establish whether DHS accepted each recommendation or provide MITRE’s substantive response.

Why procurement stability matters to security teams

CVE identifiers are connective tissue for vulnerability workflows. A security team may use them to match a vendor advisory to scanner output, identify affected assets, link a patch to a remediation ticket and communicate status to other teams. Suppliers use the same IDs to make advisories easier to correlate across products and customers.

If assignment or publication is delayed, organizations can face duplicate investigation, inconsistent references and harder asset-to-vulnerability matching. Even without a public database outage, uncertainty about staffing or contract continuity can affect the capacity to handle submissions and improve systems. The government sponsor also has significant influence over a service used by private companies and international organizations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For operational decisions, teams should use CVE as an identifier layer, not as a complete risk-management system. Confirm applicability against vendor advisories and product versions, account for asset exposure and compensating controls, and use severity or exploitability data as inputs rather than automatic priorities. NVD enrichment or a scanner’s rating may be incomplete or delayed; a CVE record and its downstream enrichment are distinct.

How the program’s structure evolved

The current model is more federated than a single intake point. Many CNAs can assign identifiers within their scopes, bringing assignment closer to affected products and distributing work across organizations. CISA said on April 23, 2025, that the program had expanded to 453 CNAs; that is CISA’s dated figure, not a guaranteed current count. CISA’s April 2025 statement

Current CVE materials list CISA and MITRE as top-level roots and describe additional roots, including ENISA, Google, JPCERT/CC, Red Hat, INCIBE and Thales. MITRE’s stated functions include the CVE Program Secretariat, top-level-root work and CNA-of-Last-Resort responsibilities. CVE program structure

Federation can distribute workload and let organizations closer to affected products make assignments. It also increases the need for common rules, consistent data quality, clear scope boundaries, escalation paths and accountability when organizations disagree. More participants may reduce dependence on a single intake point, but participation alone does not settle who is responsible for continuity or how funding is secured.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

The 2025 contract controversy revived the funding question

In April 2025, CVE’s funding and contracting arrangements again became a public concern. CISA said there had been no funding shortfall or interruption, characterizing the episode as a contract-administration problem resolved before a lapse. That is the agency’s account; it means the program did not stop operating, but it does not make the underlying continuity concern irrelevant.

The CVE Foundation argued that the episode exposed risks in depending primarily on one U.S. government sponsor and a contract with MITRE, and advocated a more independent, diversified funding model. Its position is an argument for a different governance and funding approach, not evidence that the Foundation replaced CISA, MITRE or the CVE Board. CVE Foundation’s stated goals

A USAspending record for a DHS/MITRE delivery order covering CVE- and CWE-related work lists a current award amount of about $57.8 million, approximately $24.18 million obligated in the displayed record, and an end date of March 16, 2026. These are values for that award record, not a measure of the full cost of the CVE ecosystem or proof of the program’s total funding. The public record cited here does not establish a definitive contracting arrangement after that date. USAspending delivery-order record

What a durable oversight model would measure

The 2018 request for biennial reviews points to more than contract paperwork. To assess whether a globally used service is reliable, oversight would need to examine both continuity and the quality of its work. Useful measures include:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Submission response times, backlog size and age.
  • Consistency of identifier assignment and data quality.
  • CNA performance, scope disputes and escalation outcomes.
  • Service uptime, staffing continuity and recovery plans for contract transitions.
  • Predictability of funding and progress on modernization.
  • Stakeholder complaints, appeals and how they are resolved.

A distributed CNA network can broaden participation, but clear standards and review mechanisms are needed to make distributed authority dependable. Likewise, a nonprofit funding model could reduce reliance on one sponsor, but it would need safeguards against donor influence, reliable fundraising, workable governance and continued free public access.

What the 2018 criticism means now

The program’s governance and participation have plainly evolved since the committee’s investigation. But the current organizational structure does not establish that funding dependence and procurement risk have been permanently eliminated. The 2025 episode put those questions back in view: CISA reported no interruption, while the CVE Foundation saw the contract controversy as evidence of structural vulnerability. The 2018 dispute therefore remains useful as an accountability benchmark—whether CVE has durable funding, transparent performance review and continuity plans fit for the role its identifiers play across the security ecosystem.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.