Briev
Live
Politics

Congress eyes formal legislation for global CVE vulnerability database amid AI surge

Lawmakers are debating a bill to codify the CVE vulnerability tracking program, while CISA cautions that rigid rules could limit its adaptability.

CISA sees value in formally authorizing the world’s leading software vulnerability registry, the Common Vulnerabilities and Exposures (CVE) program, but stresses that overly detailed legislative mandates could make the system too restrictive. The discussion was sparked by a funding scare last year when MITRE’s contract to run CVE was set to expire, prompting a rapid renewal that raised questions about the program’s dependence on a sole U.S. contract.

A June proposal, attached to the fiscal 2027 defense authorization bill, would embed CVE within the Department of Homeland Security, task CISA and NIST with a modernization roadmap, and establish a 15-member board comprising permanent seats for CISA, NIST and senior CVE officials plus rotating members from industry, academia, researchers and foreign governments. Although the amendment was introduced by Representatives Delia Ramirez and George Whitesides, the House Rules Committee did not schedule it for a floor vote. CISA officials note that formal recognition could secure long-term support, yet they remain wary of rules that might hinder the program’s ability to adapt to emerging challenges such as AI-driven vulnerability discovery and expanding international participation, exemplified by ENISA’s recent entry as a CVE Root authority.

Why it matters

Embedding CVE in law could stabilize a critical global security tool while preserving its ability to evolve with AI and international input.

In this story

CVEvulnerability trackingcongressional proposalAI impactinternational participationCISANISTMITREmodernization plan