Discrepancies found with Debian CVE(s)
- Dominant language
- Go
- Stars
- 2.9k
- Forks
- 369
- Avg merge
- 1d 17h
- Merged PRs (30d)
- 149
Description
Data Used from: https://osv-vulnerabilities.storage.googleapis.com/Debian/all.zip
Source used to compare against: https://security-tracker.debian.org/tracker
Case 1
---
CVE Entries marked as "NOT-FOR-US" included in the ZIP.
Example: DEBIAN-CVE-2025-0649
https://security-tracker.debian.org/tracker/CVE-2025-0649
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-0649.json
Case 2
---
CVE Entries marked as Rejected by both Debian and NVD included in the ZIP.
Example: DEBIAN-CVE-2023-52979
- Sources
- https://security-tracker.debian.org/tracker/CVE-2023-52979 (Empty Page)
- https://salsa.debian.org/security-tracker-team/security-tracker/-/raw/master/data/CVE/list (Specifically marked as Rejected)
- OSV
- https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2023-52979.json (No Indicating values to show Rejected status)
Case 3
---
Few CVE entries have wrong Debian versions marked as affected in the ZIP.
Example: DEBIAN-CVE-2025-52566
We can see that only the unstable release is mentioned at the source (Debian Security Tracker).
https://security-tracker.debian.org/tracker/CVE-2025-52566
But Debian:14 is mentioned here,
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-52566.json
Contributor guide
Assessment
This issue has not been assessed yet.