TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The curl website now features text alerting about NVD “abuse”

2 pointsby samuelophalmost 2 years ago

2 comments

samuelophalmost 2 years ago
"Alert: if you look up curl CVEs in public sources like NVD you will find they use inflated severity levels and CVSS scores. They think they know better and override our assessments. This is a systemic error that we unfortunately cannot fix. Feel free to complain to them - we keep doing it to no use - and consider using our material as the canonical sources for curl issues."
jruohonenalmost 2 years ago
While it is well-documented that there are erroneous assignments, I think it is still better that a vendor-independent body does the scoring. Though, the presence of CNAs kind of admittedly downplays this line of argumentation.