Monitoring Reporting series · Quarterly · 97 observations

OpenSSL vulnerability disclosures

Quarterly OpenSSL vulnerability disclosures, with severity and reporter-credit attribution.

49 disclosures in 2026 through 25 August 2026

Descriptive
Total
49
AI-linked
27
2025
6
2014–2023 mean
15.4

Quarterly disclosures

Quarterly OpenSSL vulnerability disclosures Quarterly total disclosures, split by public credit text. 0 12.5 25 37.5 50 2010-Q1: 4 total; 0 AI-linked credit; 4 other 2010-Q2: 2 total; 0 AI-linked credit; 2 other 2010-Q3: 0 total; 0 AI-linked credit; 0 other 2010-Q4: 3 total; 0 AI-linked credit; 3 other 2011-Q1: 1 total; 0 AI-linked credit; 1 other 2011-Q2: 0 total; 0 AI-linked credit; 0 other 2011-Q3: 2 total; 0 AI-linked credit; 2 other 2011-Q4: 0 total; 0 AI-linked credit; 0 other 2012-Q1: 8 total; 0 AI-linked credit; 8 other 2012-Q2: 3 total; 0 AI-linked credit; 3 other 2012-Q3: 0 total; 0 AI-linked credit; 0 other 2012-Q4: 0 total; 0 AI-linked credit; 0 other 2013-Q1: 3 total; 0 AI-linked credit; 3 other 2013-Q2: 0 total; 0 AI-linked credit; 0 other 2013-Q3: 0 total; 0 AI-linked credit; 0 other 2013-Q4: 2 total; 0 AI-linked credit; 2 other 2014-Q1: 2 total; 0 AI-linked credit; 2 other 2014-Q2: 7 total; 0 AI-linked credit; 7 other 2014-Q3: 9 total; 0 AI-linked credit; 9 other 2014-Q4: 4 total; 0 AI-linked credit; 4 other 2015-Q1: 20 total; 0 AI-linked credit; 20 other 2015-Q2: 6 total; 0 AI-linked credit; 6 other 2015-Q3: 2 total; 0 AI-linked credit; 2 other 2015-Q4: 4 total; 0 AI-linked credit; 4 other 2016-Q1: 10 total; 0 AI-linked credit; 10 other 2016-Q2: 8 total; 0 AI-linked credit; 8 other 2016-Q3: 14 total; 0 AI-linked credit; 14 other 2016-Q4: 3 total; 0 AI-linked credit; 3 other 2017-Q1: 4 total; 0 AI-linked credit; 4 other 2017-Q2: 0 total; 0 AI-linked credit; 0 other 2017-Q3: 1 total; 0 AI-linked credit; 1 other 2017-Q4: 3 total; 0 AI-linked credit; 3 other 2018-Q1: 2 total; 0 AI-linked credit; 2 other 2018-Q2: 2 total; 0 AI-linked credit; 2 other 2018-Q3: 0 total; 0 AI-linked credit; 0 other 2018-Q4: 3 total; 0 AI-linked credit; 3 other 2019-Q1: 2 total; 0 AI-linked credit; 2 other 2019-Q2: 0 total; 0 AI-linked credit; 0 other 2019-Q3: 4 total; 0 AI-linked credit; 4 other 2019-Q4: 1 total; 0 AI-linked credit; 1 other 2020-Q1: 0 total; 0 AI-linked credit; 0 other 2020-Q2: 1 total; 0 AI-linked credit; 1 other 2020-Q3: 1 total; 0 AI-linked credit; 1 other 2020-Q4: 1 total; 0 AI-linked credit; 1 other 2021-Q1: 5 total; 0 AI-linked credit; 5 other 2021-Q2: 0 total; 0 AI-linked credit; 0 other 2021-Q3: 2 total; 0 AI-linked credit; 2 other 2021-Q4: 1 total; 0 AI-linked credit; 1 other 2022-Q1: 2 total; 0 AI-linked credit; 2 other 2022-Q2: 5 total; 0 AI-linked credit; 5 other 2022-Q3: 3 total; 0 AI-linked credit; 3 other 2022-Q4: 3 total; 0 AI-linked credit; 3 other 2023-Q1: 12 total; 0 AI-linked credit; 12 other 2023-Q2: 1 total; 0 AI-linked credit; 1 other 2023-Q3: 4 total; 0 AI-linked credit; 4 other 2023-Q4: 2 total; 0 AI-linked credit; 2 other 2024-Q1: 3 total; 0 AI-linked credit; 3 other 2024-Q2: 4 total; 0 AI-linked credit; 4 other 2024-Q3: 1 total; 0 AI-linked credit; 1 other 2024-Q4: 1 total; 0 AI-linked credit; 1 other 2025-Q1: 2 total; 0 AI-linked credit; 2 other 2025-Q2: 1 total; 0 AI-linked credit; 1 other 2025-Q3: 3 total; 3 AI-linked credit; 0 other 2025-Q4: 0 total; 0 AI-linked credit; 0 other 2026-Q1: 13 total; 12 AI-linked credit; 1 other 2026-Q2: 25 total; 15 AI-linked credit; 10 other 2026-Q3: 11 total; 0 AI-linked credit; 11 other; partial period 2010 2014 2018 2022 2026
Other credit AI-linked credit Latest period through 25 August 2026.

2026 severity and credit text

Low
37
Medium+
12
Explicit AI
1
AI affiliation
26
AI-linked total
27
Provenance files

283 records · snapshot 18c7d2226fd3 · data through 2026-08-25

Fixed-codebase series

Series20252026AI-linkedThrough
curl disclosures945222 September 2026
OpenSSL disclosures6492725 August 2026
Series definition
Measure
One CVE record in OpenSSL's official release-metadata repository, counted in the quarter of its public date.
Counting
Read every dated CVE record from one pinned official metadata snapshot, aggregate by public-date quarter, and preserve missing quarters as explicit zeros.
Date
Use `containers.cna.datePublic` from the official CVE record. The final quarter ends at the latest source date and is marked incomplete.
Denominator
All official OpenSSL vulnerability disclosures in the quarter. No denominator for search effort, submissions, compute, or researcher time is available.
AI-linked credit
Four mutually exclusive reporter-credit bands: explicit AI marker, AI affiliation only, fuzzing marker, and other or unmarked. The compact quarterly numerator combines the first two and remains noisy attribution evidence.
Frequency
Quarterly
Data and sources

Fetch or load the committed official OpenSSL metadata snapshot, normalize one row per CVE, preserve official severity and reporter-credit bands, fill zero quarters, and rebuild the compact observations.

Download observations

Analysis and limits

Analysis

A negative-binomial or Poisson count model with calendar time, a post-2025 level and slope term, quarter effects, and an exposure offset for incomplete periods. Model choice follows dispersion diagnostics.

  • Compare 2025 and partial 2026 with several pre-period windows
  • Exclude the incomplete final quarter
  • Use annual counts to reduce release-batching sensitivity
  • Separate explicit AI markers, AI-affiliation-only credits, and total disclosures
  • Estimate Low and Medium-or-higher disclosure rates separately
  • Estimate curl and OpenSSL jointly with project-specific levels and trends

Limits

  • Disclosure volume depends on search effort, incentives, project policy, triage, and release timing.
  • A reporter credit can omit AI use or name an AI organization even when a model did not produce the finding.
  • More disclosures, especially low-severity findings, need not imply more important security progress.
  • The final 2026-Q3 observation is incomplete through 13 August 2026.
  • A repeated pattern across curl and OpenSSL remains vulnerable to common non-AI causes.
  • Two software projects are reporting controls, not a representative measure of science.
Recent data
QuarterTotalAI-linkedCoverage
2024-Q4 1 0 Complete
2025-Q1 2 0 Complete
2025-Q2 1 0 Complete
2025-Q3 3 3 Complete
2025-Q4 0 0 Complete
2026-Q1 13 12 Complete
2026-Q2 25 15 Complete
2026-Q3 11 0 Through 25 August 2026