Published October 2, 2026 · Added October 3, 2026

GNOME security lead says maintainers must accept AI-generated vulnerability reports

GNOME developer and security-tracker maintainer Michael Catanzaro argues in a blog post that AI vulnerability scanning is now essential for quality software and that maintainers who ban AI-generated issue reports are sticking their heads in the sand, saying the overwhelming majority of vulnerability reports in 2026 are AI-generated and that projects prohibiting them might as well ban vulnerability reports entirely. He calls on GNOME maintainers to rewrite their AI contribution policies to permit AI-generated vulnerability reports, warns that projects which continue to prohibit them 'are no longer suitable dependencies for GNOME' and should be developed outside GNOME GitLab, and acknowledges the downsides that have driven the bans, including verbose reports that exaggerate severity or fabricate stack traces and the toll on volunteer maintainers. The post documents GNOME's CVE counts rising from 21 in 2021 to 141 so far in 2026 (74 excluding GIMP, Gegl, libxml2 and libxslt, a pace he projects at 188 for the year) and WebKitGTK reaching 305 CVEs this year, mostly from AI analysis of bundled Skia and ANGLE. Catanzaro also discloses that he ended GNOME's bug bounty program, sponsored by Germany's Sovereign Tech Agency, because he was overwhelmed by AI-generated reports: it accepted 71 of 298 reports and paid EUR 183,900, and he has now stopped tracking new issue reports because nobody volunteered to take over.

GNOME developer and security-tracker maintainer Michael Catanzaro argues in a blog post that AI vulnerability scanning is now essential for quality software and that maintainers who ban AI-generated issue reports are sticking their heads in the sand, saying the overwhelming majority of vulnerability reports in 2026 are AI-generated and that projects prohibiting them might as well ban vulnerability reports entirely. He calls on GNOME maintainers to rewrite their AI contribution policies to permit AI-generated vulnerability reports, warns that projects which continue to prohibit them ‘are no longer suitable dependencies for GNOME’ and should be developed outside GNOME GitLab, and acknowledges the downsides that have driven the bans, including verbose reports that exaggerate severity or fabricate stack traces and the toll on volunteer maintainers. The post documents GNOME’s CVE counts rising from 21 in 2021 to 141 so far in 2026 (74 excluding GIMP, Gegl, libxml2 and libxslt, a pace he projects at 188 for the year) and WebKitGTK reaching 305 CVEs this year, mostly from AI analysis of bundled Skia and ANGLE. Catanzaro also discloses that he ended GNOME’s bug bounty program, sponsored by Germany’s Sovereign Tech Agency, because he was overwhelmed by AI-generated reports: it accepted 71 of 298 reports and paid EUR 183,900, and he has now stopped tracking new issue reports because nobody volunteered to take over.

Read the original story.

Source: GNOME Foundation