Authorization enables Chainguard to assign CVEs for qualifying open source vulnerabilities processed through Athena, helping protect open source software from AI attacks
NEW YORK, Sept. 22, 2026 /PRNewswire/ — Chainguard, the trusted source for open source, today announced that it has been authorized by the Common Vulnerabilities and Exposures (CVE®) Program as a CVE Numbering Authority (CNA). The mission of the CVE Program is to identify, define, and catalog publicly disclosed cybersecurity vulnerabilities. As a CNA, Chainguard can assign CVE identifiers and publish CVE Records for qualifying vulnerabilities. The authorization is scoped to include open source vulnerabilities processed through the Athena coalition, when upstream maintainers have already fixed the flaw without an identifier, no maintainer remains to assign one, or no more specific CNA covers the project.
This milestone underscores Chainguard’s deep commitment to transparent, coordinated vulnerability disclosure and protecting open source software from AI attacks. Frontier AI models are surfacing latent vulnerabilities in widely used open source software that traditional security tools and years of expert review failed to detect. As AI compresses the time between discovery and exploitation, vulnerabilities without CVE identifiers may remain invisible to the scanners, databases, and compliance systems organizations rely on to identify and prioritize risk.
“AI-driven zero-day discovery is pushing traditional approaches to vulnerability handling and disclosure to the breaking point,” said Quincy Castro, Chief Information Security Officer, Chainguard. “Through Athena, we are working to get fixes as quickly as possible into as many hands as possible. Becoming a CNA allows us to communicate about vulnerability fixes in a ‘language’ familiar to many organizations and open source maintainers.”
The designation strengthens Athena, Chainguard’s industry coalition for the orchestrated defense of open source software, by providing precise affected and fixed version ranges and technical details that help organizations assess their exposure, reduce false positives, and take appropriate action. Chainguard’s CVE Records also defer to maintainers and project-specific CNAs wherever they exist. With the help of coalition members and mitigation partners, such as Akamai, BNY, Cisco, Cloudflare, JPMorganChase, Kyndryl, Morgan Stanley, and Upwind, Athena validates AI-discovered vulnerabilities, and develops fixes, then partners with Akrites to carry vulnerabilities through disclosure and toward durable upstream remediation.
To learn more about how Chainguard advances open source vulnerability discovery through Athena, visit chainguard.dev/athena.
About Chainguard
Chainguard is the trusted source for open source. By providing engineers and AI agents with hardened, trusted, and production-ready artifacts, Chainguard helps organizations prevent AI supply chain attacks, increase engineering velocity while reducing toil, and maintain continuous compliance. Customers include Fortune 500 enterprises and global industry leaders, including Anduril, Canva, DocuSign, OpenAI, Public Storage, Snap Inc., and Snowflake. Chainguard is venture-backed by leading investors, including Amplify, IVP, Kleiner Perkins, Lightspeed Venture Partners, Mantis VC, Redpoint Ventures, Sequoia Capital, and Spark Capital. For more information, visit: https://www.chainguard.dev/
Brittany Hendrickson, [email protected]
SOURCE Chainguard





