Monitoring
Reporting series · Quarterly · 97 observations
OpenSSL vulnerability disclosures
Quarterly OpenSSL vulnerability disclosures, with severity and reporter-credit attribution.
49 disclosures in 2026 through 25 August 2026
Descriptive- Total
- 49
- AI-linked
- 27
- 2025
- 6
- 2014–2023 mean
- 15.4
Quarterly disclosures
2026 severity and credit text
- Low
- 37
- Medium+
- 12
- Explicit AI
- 1
- AI affiliation
- 26
- AI-linked total
- 27
Provenance files
283 records · snapshot 18c7d2226fd3 · data through 2026-08-25
Fixed-codebase series
| Series | 2025 | 2026 | AI-linked | Through |
|---|---|---|---|---|
| curl disclosures | 9 | 45 | 22 | 2 September 2026 |
| OpenSSL disclosures | 6 | 49 | 27 | 25 August 2026 |
Series definition
- Measure
- One CVE record in OpenSSL's official release-metadata repository, counted in the quarter of its public date.
- Counting
- Read every dated CVE record from one pinned official metadata snapshot, aggregate by public-date quarter, and preserve missing quarters as explicit zeros.
- Date
- Use `containers.cna.datePublic` from the official CVE record. The final quarter ends at the latest source date and is marked incomplete.
- Denominator
- All official OpenSSL vulnerability disclosures in the quarter. No denominator for search effort, submissions, compute, or researcher time is available.
- AI-linked credit
- Four mutually exclusive reporter-credit bands: explicit AI marker, AI affiliation only, fuzzing marker, and other or unmarked. The compact quarterly numerator combines the first two and remains noisy attribution evidence.
- Frequency
- Quarterly
Data and sources
Fetch or load the committed official OpenSSL metadata snapshot, normalize one row per CVE, preserve official severity and reporter-credit bands, fill zero quarters, and rebuild the compact observations.
- OpenSSL release metadata · Primary Data
- METR — LLMs' Contribution to Discoveries · External Reference
Analysis and limits
Analysis
A negative-binomial or Poisson count model with calendar time, a post-2025 level and slope term, quarter effects, and an exposure offset for incomplete periods. Model choice follows dispersion diagnostics.
- Compare 2025 and partial 2026 with several pre-period windows
- Exclude the incomplete final quarter
- Use annual counts to reduce release-batching sensitivity
- Separate explicit AI markers, AI-affiliation-only credits, and total disclosures
- Estimate Low and Medium-or-higher disclosure rates separately
- Estimate curl and OpenSSL jointly with project-specific levels and trends
Limits
- Disclosure volume depends on search effort, incentives, project policy, triage, and release timing.
- A reporter credit can omit AI use or name an AI organization even when a model did not produce the finding.
- More disclosures, especially low-severity findings, need not imply more important security progress.
- The final 2026-Q3 observation is incomplete through 13 August 2026.
- A repeated pattern across curl and OpenSSL remains vulnerable to common non-AI causes.
- Two software projects are reporting controls, not a representative measure of science.
Recent data
| Quarter | Total | AI-linked | Coverage |
|---|---|---|---|
| 2024-Q4 | 1 | 0 | Complete |
| 2025-Q1 | 2 | 0 | Complete |
| 2025-Q2 | 1 | 0 | Complete |
| 2025-Q3 | 3 | 3 | Complete |
| 2025-Q4 | 0 | 0 | Complete |
| 2026-Q1 | 13 | 12 | Complete |
| 2026-Q2 | 25 | 15 | Complete |
| 2026-Q3 | 11 | 0 | Through 25 August 2026 |