# cve reporting

Published articles for cve reporting.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## NIS2: Understanding key software security requirements

DevFeed: [NIS2: Understanding key software security requirements](<https://devfeed.tech/articles/nis2-understanding-key-software-security-requirements-13185.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/nis2-understanding-key-software-security-requirements>)

Published: 2025-02-25T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [vulnerability management](<https://devfeed.tech/topics/vulnerability-management.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Development](<https://devfeed.tech/topics/development.md>)

Tags: [compliance](<https://devfeed.tech/tags/compliance.md>), [cve-management](<https://devfeed.tech/tags/cve-management.md>), [cve-reporting](<https://devfeed.tech/tags/cve-reporting.md>), [energy](<https://devfeed.tech/tags/energy.md>), [eu](<https://devfeed.tech/tags/eu.md>), [europe](<https://devfeed.tech/tags/europe.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [manufacturing](<https://devfeed.tech/tags/manufacturing.md>), [nis2](<https://devfeed.tech/tags/nis2.md>), [risk-management](<https://devfeed.tech/tags/risk-management.md>), [sboms](<https://devfeed.tech/tags/sboms.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>), [transportation](<https://devfeed.tech/tags/transportation.md>), [vulnerability-management](<https://devfeed.tech/tags/vulnerability-management.md>)

### AI overview

This article explains how the European Union's NIS2 directive expands software security and vulnerability management requirements, shifts accountability to management and boards, and affects organizations operating in the EU. It discusses software supply chain security, open source development, SBOMs, CVE reporting, risk management, and the workload these requirements may create for security and developer teams.

### Source excerpt

The European Union's Network and Information Systems 2 is a compliance framework with strict requirements around vulnerability management.

## Explore Chainguard CVE Visualizations: Now in Beta

DevFeed: [Explore Chainguard CVE Visualizations: Now in Beta](<https://devfeed.tech/articles/explore-chainguard-cve-visualizations-now-in-beta-13037.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/explore-chainguard-cve-visualizations-now-in-beta>)

Published: 2024-12-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Docker Hardened Images](<https://devfeed.tech/topics/docker-hardened-images.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [grype](<https://devfeed.tech/topics/grype.md>), [trivy](<https://devfeed.tech/topics/trivy.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [blog](<https://devfeed.tech/tags/blog.md>), [business](<https://devfeed.tech/tags/business.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [comparisons](<https://devfeed.tech/tags/comparisons.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-reporting](<https://devfeed.tech/tags/cve-reporting.md>), [cve-visualizations](<https://devfeed.tech/tags/cve-visualizations.md>), [cves](<https://devfeed.tech/tags/cves.md>), [developer](<https://devfeed.tech/tags/developer.md>), [grype](<https://devfeed.tech/tags/grype.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [trivy](<https://devfeed.tech/tags/trivy.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Chainguard announces the beta release of CVE Visualizations in its console. The capability compares Chainguard Images with alternative container images over time using total CVEs, severity-level trends, and image size, helping organizations communicate security, engineering, and economic benefits.

### Source excerpt

Check out Chainguard CVE Visualizations, a new capability that allows for comparisons of CVE numbers between Chainguard Images and alternative container images.

## Vulnerability disclosure: Which comes first, the security bug in PHP or the CVE?

DevFeed: [Vulnerability disclosure: Which comes first, the security bug in PHP or the CVE?](<https://devfeed.tech/articles/vulnerability-disclosure-which-comes-first-the-security-bug-in-php-or-the-cve-8227.md>)

Original publisher: [Read original article](<https://snyk.io/blog/vulnerability-disclosure-php-use-after-free/>)

Author: Liran Tal; DeveloperSteve Coochin

Published: 2023-12-19T06:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [PHP](<https://devfeed.tech/topics/php.md>), [Security](<https://devfeed.tech/topics/security.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>)

Tags: [application-security](<https://devfeed.tech/tags/application-security.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [bug](<https://devfeed.tech/tags/bug.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-reporting](<https://devfeed.tech/tags/cve-reporting.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [incident](<https://devfeed.tech/tags/incident.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [php](<https://devfeed.tech/tags/php.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [snyk](<https://devfeed.tech/tags/snyk.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-disclosure](<https://devfeed.tech/tags/vulnerability-disclosure.md>)

### AI overview

This article examines the disclosure of a PHP Use After Free vulnerability and the difficulties of getting security reports recognized, fixed, and published as CVEs. It follows the dompdf incident timeline, including delayed maintainer responses, public disclosure, exploitation leading to a reverse shell, and the eventual CVE assignment.

### Source excerpt

In this post, we cover the CVE reporting process using the Use After Free vulnerability type as an example.