Long delay in CVE assignment #203590
Replies: 1 comment
|
Twenty days is well beyond GitHub's documented normal window. GitHub says CVE requests made through a repository security advisory are usually reviewed within 72 hours. The maintainer should first open the draft advisory and confirm that the CVE field still shows a pending request. Only an advisory administrator can inspect or manage that request, so the reporter will need to coordinate with the maintainer rather than submit a second request independently. If it is still pending, the maintainer should contact GitHub Support and include only the routing information needed to locate it:
Do not paste embargoed vulnerability details into a public ticket or this discussion. GitHub's Support documentation says GitHub Free accounts can still contact Support for account, security, and abuse issues, so this should be routed as a security-advisory/CVE issue rather than ordinary technical support. Before escalating, also verify that the project is not already covered by another CVE Numbering Authority. GitHub documents that it cannot assign a CVE when another CNA covers the project. I would not cancel and re-request the CVE just to restart the clock; the API documents duplicate/spammed requests as a possible validation failure, and keeping the original request gives Support a clean audit trail. Official references:
So the next action is: have a maintainer/advisory admin open a security-category Support request referencing the existing GHSA and original request date. |
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Question
💬 Feature/Topic Area
Code quality
Discussion Details
Hi everyone,
I found a vulnerability in semaphoreUI CVSS: 9.8 (GHSA-xp7j-h7jc-4w8p) and the vuln has been patched/fixed and the advisory is in draft. The maintainer requested the CVE on 12th July, but the CVE has not been assigned yet. It has been 20 days almost. Who should I reach out to? Is anyone else facing the same delay.
Thanks
All reactions