- Sources: JFrog research, HN discussion
- Summary: JFrog audited 55 advisories submitted from a single GitHub account and found 54 of them fabricated, among them six SQLite CVEs that NVD had rated critical or high. The post names checkable red flags for a fabricated record: no entry on the maintainer's own advisory page, no linked commit or pull request, empty CPE fields, and code references that do not exist in the claimed version. The post is dated 2026-07-30 and reached the Hacker News front page on 2026-08-03. The records are still moving: JFrog records Red Hat scoring CVE-2026-51302 at 10.0 Critical and downgrading it to 7.6 High between two days of writing, and JFrog reported the findings to GHSA, Red Hat and NVD.
- Why it matters: The MITRE submission form verifies no identity and no step in the pipeline requires a reproducible proof of concept, so a fabricated advisory reaches GHSA, downstream databases, and enterprise scanners carrying a critical score.
- Follow-up: Track whether GHSA, Red Hat and NVD withdraw or rescore the disputed records.
send feedback on this story