The Cloud Security Alliance’s AI Safety Initiative published a research note tracing how AI-assisted vulnerability discovery has outrun open source remediation capacity, cataloguing intake channels that were ended, paused or restructured between January and October 2026. curl ended its paid bug bounty in January to remove the incentive for low-effort submissions and cut load on its security team; HackerOne paused new Internet Bug Bounty submissions in April over the imbalance between AI-accelerated discovery and maintainers’ ability to fix findings; the Linux kernel rewrote its security reporting guidance after Linus Torvalds said duplicate AI-found reports had made the private list hard to manage; and Google’s Open Source Software Vulnerability Reward Program stopped accepting new product vulnerability submissions on October 1 under a reform promised for Q1 2027. The note separates fabricated or low-quality reports, which it frames as largely an incentive and filtering problem, from valid but redundant findings that filtering cannot fix, pointing to its analysis of Anthropic’s Project Glasswing, where more than 10,000 high- and critical-severity candidates produced only about 6 percent of 1,596 disclosed vulnerabilities patched by May 22, 2026, and to NIST’s plan to limit full NVD enrichment to an estimated 15 to 20 percent of anticipated CVE volume. It argues that enterprises consuming open source should treat maintainer capacity as a supply-chain risk factor, that slower triage and fewer funded disclosure channels plausibly widen the gap between discovery and a published fix, and that organisations using AI to find flaws in other people’s code take on an obligation to validate findings and, where possible, contribute fixes.
When Discovery Outruns Remediation: Open-Source Disclosure Strain
The Cloud Security Alliance's AI Safety Initiative published a research note tracing how AI-assisted vulnerability discovery has outrun open source remediation capacity, cataloguing intake channels that were ended, paused or restructured between January and October 2026. curl ended its paid bug bounty in January to remove the incentive for low-effort submissions and cut load on its security team; HackerOne paused new Internet Bug Bounty submissions in April over the imbalance between AI-accelerated discovery and maintainers' ability to fix findings; the Linux kernel rewrote its security reporting guidance after Linus Torvalds said duplicate AI-found reports had made the private list hard to manage; and Google's Open Source Software Vulnerability Reward Program stopped accepting new product vulnerability submissions on October 1 under a reform promised for Q1 2027. The note separates fabricated or low-quality reports, which it frames as largely an incentive and filtering problem, from valid but redundant findings that filtering cannot fix, pointing to its analysis of Anthropic's Project Glasswing, where more than 10,000 high- and critical-severity candidates produced only about 6 percent of 1,596 disclosed vulnerabilities patched by May 22, 2026, and to NIST's plan to limit full NVD enrichment to an estimated 15 to 20 percent of anticipated CVE volume. It argues that enterprises consuming open source should treat maintainer capacity as a supply-chain risk factor, that slower triage and fewer funded disclosure channels plausibly widen the gap between discovery and a published fix, and that organisations using AI to find flaws in other people's code take on an obligation to validate findings and, where possible, contribute fixes.
Source: Cloudsecurityalliance