Publishing security fixes without CVE numbers

Hauke Mehrtens hauke at hauke-m.de
Wed Jun 10 03:09:24 PDT 2026


Hi,

It takes a long time to get a CVE number assigned for a problem. In the 
past using the github advisory worked in ~2 business days, we are 
waiting for them over 1 week now. Directly over MITRE never worked for 
me, I waited there 2 weeks in the past and did not got an answer.

I think we should publish fixes for security problems without a CVE 
number. If someone wants to assign a number to it later anyone can do this.
Currently getting a CVE number delays the fixing of security problems by 
days or weeks and also takes effort on our side.

Maybe the people at openwall have an idea:
https://www.openwall.com/lists/oss-security/2026/06/10/1

If this does not improve I suggest to not wait for a CVE number with 
publishing fixes and details about a security problem in the future.

Hauke



More information about the openwrt-adm mailing list