Skip to main content

Athena

Chainguard Becomes CVE Numbering Authority to Fight AI-Found Flaws

Image
Chainguard Becomes CVE Numbering Authority to Fight AI-Found Flaws

New York – September 22, 2026 -- Chainguard has been authorized by the CVE Program as a CVE Numbering Authority (CNA), granting it the power to assign official vulnerability identifiers for qualifying open source flaws surfaced through its Athena coalition.

Chainguard gains authority to assign CVE identifiers for unclaimed open source flaws

The CNA scope covers cases where upstream maintainers have already fixed a flaw without issuing an identifier, where no maintainer remains to assign one, or where no more specific CNA covers the affected project. Chainguard's CVE Records will defer to maintainers and project-specific CNAs wherever they exist.