[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-83991-en":3,"doc-seo-83991-105":29,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":13,"seo_description":14,"update_tm":27,"read_time":28},83991,7971461740886,"Theodore","https://ap-avatar.wpscdn.com/davatar_3d24733baf745e90a7e4bdd5f77d97b2",8,"Research & Report","The Cathedral and the Bazaar of Software Vulnerabilities: From the NVD to the CNAs","Decades after the National Vulnerability Database (NVD) established itself as a “cathedral” reference for vulnerability information, the CVE ecosystem has expanded into a “bazaar” of multiple CVE Numbering Authorities (CNAs) that may assign diverging severity assessments. The study performs a systematic analysis of divergence in CVSS metrics across NVD and public CNAs, including self-divergence within the same CNA. Root causes are investigated via qualitative outreach and discussion in FIRST’s CVSS Special Interest Group, with findings on practice and research implications and model generalization limits.","The Cathedral and the Bazaar of Software Vulnerabilities: From the NVD to the CNAs  \nSiqi Zhang, Fabio Massacci, and Mengyuan Zhang  \narXiv :2607 .05670v 1 [ cs . SE] 6 Jul 2026  \nAbstract—For decades, the National Vulnerability Database (NVD), the “Cathedral”, has been the reference source for vulnerability information for downstream research and industry tasks, e.g., software update prioritization. An emerging “Bazaar”of diverse CVE Numbering Authorities (CNAs) has created many alternative and sometimes diverging sources. We conduct a systematic analysis of divergence in Common Vulnerability Scoring System (CVSS) metrics covering the NVD and the public CNAs. We also check for self-divergence: two identical textual descriptions of CVEs with identical CWEs are rated differently by the same CNA. The odds of diverging are widespread, not uniform and sometimes unexpected. The assessment of Attack Complexity, User Interaction, and Impact are the major metrics where divergence happens. To understand the root causes, we perform a qualitative study by reaching out to the NVD and other CNAs (both open sources and proprietary products). We also discussed the findings at the CVSS Special Interest Group of FIRST, the community responsible for maintaining and evolving the CVSS standard. The key insights are that while something might be due to human errors, in some cases diverging is actually the right thing to do and might require changes in the way CVEs are generated industry-wide, in other cases explaining divergence requires access to additional FAQs. The good news is that the situation is improving since 2025, the bad news is that if one downloads the whole NVD (or another CNA dataset) from several years and uses it for predictions, the models trained on one source do not reliably generalize to a different source (accuracy can drop by 40%). We discuss the implications for practice and research.  \nIndex Terms—Vulnerability Scoring System, CNAs, NVD, Patch Management, Inconsistency  \nI. INTRODUCTION  \nEric Raymond [1] introduced the word bazaar in 1998 to positively describe distributed and collaborative software development for Linux. The code is developed by the public as opposed to the cathedral, a single authoritative source.  \nFor decades, the National Vulnerability Database (NVD) has served as the software vulnerability cathedral, the source for severity assessment. Many governmental mandates (e.g., US Executive Orders), industry regulations (e.g., Credit Cards’PCI Security), and many research papers, such as vulnerability prioritization systems [2], security posture monitoring tools [3], and security metric frameworks [4], rely on NVD data as a foundational input. Correctness and consistency of these data directly affect the reliability of downstream services (See detailed list in Table VIII) .  \nSiqi Zhang, Fabio Massacci, and Mengyuan Zhang are with Vrije Universiteit Amsterdam, Amsterdam, The Netherlands. E-mail:{s.zhang4,f.massacci,[m.zhang](m.zhang}@vu.nl)[}](m.zhang}@vu.nl)[@vu.nl](m.zhang}@vu.nl).  \nFabio Massacci is also with University of Trento, Trento, Italy. E-mail: fabio.massacci@unitn.it.  \nNumber of CVE Entrie  \n5000  \n4000  \n3000  \n2000  \n1000  \n0  \n10 20 30 40 50 CNAs Ranked by \\# of Common CVE Entrie  \n(b) Severity Levels  \nFig. 1: The growth of CNAs and severity disagreements  \nVulnerabilities boomed and, to scale, the CVE program introduced the CVE Numbering Authority (CNA) framework, authorizing registered CNAs (e.g., Microsoft) to independently create CVE entries and assign severity assessments. Fig. 1a shows the growth in the number of CNAs following the CVE program’s decision in 2016 [5] . As of 2024, CNAs have issued a substantial portion of the total CVEs. The bazaar of software vulnerability assessment was born and is now thriving. Fig. 1b illustrates the differences in severity scored by the NVD and the severity of the same vulnerability scored by a CNA. To decide vulnerability prioritization, researc","cbCaiv71ZI9goHIz","https://ap.wps.com/l/cbCaiv71ZI9goHIz","pdf",3049943,1,18,"English","en",105,"# Introduction\n## Background: NVD as the Cathedral and CNAs as the Bazaar\n## Prior Work on Divergence\n## Research Gap and This Paper’s Contributions","[{\"question\":\"What problem does the paper address regarding vulnerability information sources?\",\"answer\":\"It addresses divergence between NVD and CNA-assigned CVSS severity assessments, and also divergence within the same CNA for otherwise identical CVE descriptions and CWEs.\"},{\"question\":\"Which parts of the CVSS are most associated with divergence?\",\"answer\":\"The paper highlights Attack Complexity, User Interaction, and Impact as the major metrics where divergence happens.\"},{\"question\":\"What is the practical impact for prediction models trained on one dataset source?\",\"answer\":\"Models trained on one source do not reliably generalize to another source; accuracy can drop by as much as 40% when transferring across sources.\"}]",1784191891,45,{"code":4,"msg":30,"data":31},"ok",{"site_id":24,"language":23,"slug":32,"title":13,"keywords":33,"description":14,"schema_data":34,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":27},"the-cathedral-and-the-bazaar-of-software-vulnerabilities-from-the-nvd-to-the-cnas","",{"@graph":35,"@context":85},[36,53,68],{"@type":37,"itemListElement":38},"BreadcrumbList",[39,43,47,50],{"item":40,"name":41,"@type":42,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":44,"name":45,"@type":42,"position":46},"https://docshare.wps.com/document/","Document",2,{"item":48,"name":12,"@type":42,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":42,"position":52},"https://docshare.wps.com/document/the-cathedral-and-the-bazaar-of-software-vulnerabilities-from-the-nvd-to-the-cnas/83991/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":23,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":40,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-25","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the paper address regarding vulnerability information sources?","Question",{"text":75,"@type":76},"It addresses divergence between NVD and CNA-assigned CVSS severity assessments, and also divergence within the same CNA for otherwise identical CVE descriptions and CWEs.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Which parts of the CVSS are most associated with divergence?",{"text":80,"@type":76},"The paper highlights Attack Complexity, User Interaction, and Impact as the major metrics where divergence happens.",{"name":82,"@type":73,"acceptedAnswer":83},"What is the practical impact for prediction models trained on one dataset source?",{"text":84,"@type":76},"Models trained on one source do not reliably generalize to another source; accuracy can drop by as much as 40% when transferring across sources.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":45,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":46,"doc_module":4,"doc_module_name":45,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":45,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":45,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":45,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":45,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":45,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":45,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":45,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":45,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":45,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]