OpenJS Foundation Halts CVE Triage Across 40+ JavaScript Projects, Citing a Flood of AI-Generated Security Reports

From September 17 to October 6, 2026, Node.js, Express and dozens of other projects are not processing new vulnerability reports, following a rejection rate of up to 90% on some packages.

EduFabTech Β· 29 September 2026 Β· 4 min read Β· 6 views
A 90% rejection-rate ring anchors the headline, with a "Triage Paused" badge showing the Sep 17–Oct 6, 2026 window across 40+ JS projects.
EduFabTech · Own work

From September 17 to October 6, 2026, the OpenJS Foundation's CVE Numbering Authority (CNA) is not triaging, validating or assigning CVE identifiers for any of the more than 40 JavaScript projects it covers, including Node.js, Electron, ESLint, Fastify and webpack. The foundation says the pause is a direct response to a volume of AI-generated vulnerability reports that its volunteer security teams can no longer keep up with.

The break is coordinated, not unilateral. Express, one of the most widely deployed web frameworks in the Node.js ecosystem, announced on September 9, 2026 that it was joining, suspending triage, patch development, advisory validation, CVE assignment and security releases for the same three-week window. Report channels stay open throughout, but submitters should not expect a response until October 7. The one exception is a vulnerability that is actively being exploited, or a critical issue posing immediate and serious risk: the foundation says it will still respond to those if flagged through its Slack, though it does not commit to a specific turnaround time.

A bar chart contrasts 3 CVEs published in H2 2025 against 49 in H1 2026, alongside the AI-scanning and rejection-rate stats behind the surge.
A bar chart contrasts 3 CVEs published in H2 2025 against 49 in H1 2026, alongside the AI-scanning and rejection-rate stats behind the surge.EduFabTech · Own work

The numbers behind the decision

The foundation laid out the workload shift in its own Q2 2026 security update, published July 8, 2026. Across the two years before that update, the CNA had logged 352 reports through HackerOne. Volume then jumped sharply: February 2026 saw a 4.6-times increase in submissions, which the foundation attributes to the arrival of AI agent-assisted scanning tools, and March 2026 alone brought 65 reports. On two of the foundation's highest-traffic projects, Express and Lodash, the update states plainly that "70 to 90% of what comes in is rejected."

That rejection rate is the crux of the problem. A scanning tool can generate a plausible-looking vulnerability report in seconds; confirming or refuting it still requires a human who understands the codebase to read the code, reproduce the claim, and write a rejection if it doesn't hold up. The foundation's CVE output shows the strain: it published 3 CVEs in the second half of 2025 and 49 in the first half of 2026, a jump the security update attributes to heavier triage effort and AI-assisted scanning surfacing candidates faster than manual research turns them up, rather than to a real wave of new bugs. Some of that load did get more manageable: a June 2026 Node.js security release patched 18 vulnerabilities across all active release lines β€” more than double the usual 6 to 7 patches per release β€” by streamlining a 36-step review procedure down to 7 steps. Even with that gain, capacity evidently didn't grow fast enough to absorb the new volume without a scheduled break.

A model borrowed from curl

OpenJS is explicit that it is following a precedent set by curl, the widely used command-line transfer tool and library maintained largely by Daniel Stenberg. Curl paused new vulnerability submissions from July 1 to August 3, 2026, a period Stenberg called the "summer of bliss." Stenberg had already laid out the reason on curl's own blog: a confirmed-vulnerability rate that ran "north of 15%" in previous years had "plummeted to below 5%" by early 2025, with submissions increasingly describing functions that don't exist in curl's codebase or bugs already patched years earlier. LWN.net's coverage of the pause quotes Stenberg saying the team had "been under a huge pressure for the last four months or so" and needed rest; he also encouraged other open-source projects to consider similar breaks rather than treating the workload as a fixed cost of maintaining widely used software.

A three-stage pipeline traces AI report flood β†’ overwhelmed volunteers β†’ coordinated pause, with a callout on the curl precedent OpenJS is following.
A three-stage pipeline traces AI report flood β†’ overwhelmed volunteers β†’ coordinated pause, with a callout on the curl precedent OpenJS is following.EduFabTech · Own work

What the pause does and doesn't fix

Neither curl's break nor OpenJS's addresses the underlying cause: nothing stops a scanning tool or a report author from submitting through GitHub or email during the pause, and both projects say backlogged reports will simply queue for processing once triage resumes on October 7. What the break buys is recovery time for the small teams doing the reading, and a chance to redesign intake so that low-signal submissions are filtered before they reach a human. The foundation's own framing is that "AI has lowered the barrier to generating security reports, but not the cost of handling them" β€” the asymmetry between how cheaply a report can now be produced and how expensive it still is to check is the thing both projects are trying to buy time against.

The OpenJS CNA was only approved in May 2025, and at that point it was authorized to issue CVE identifiers for more than 40 projects spanning "Impact," "At Large," "Incubating" and "Emeritus" tiers, with Node.js and Express among the highest-profile. For engineers and researchers who depend on that pipeline to know when a dependency needs patching, the practical effect of the pause is a three-week gap in new CVE assignments for one of the largest package ecosystems in software β€” a gap the foundation is choosing deliberately, rather than one that crept up on it unannounced.


References
  1. OpenJS Foundation. The OpenJS Foundation CNA Is Taking a Coordinated Break. OpenJS Foundation, 2026. link
  2. OpenJS Foundation. OpenJS Foundation Security Update: Q2 2026. OpenJS Foundation, 2026. link
  3. Express.js Security Team. Express is joining the OpenJS CNA coordinated break. Express.js (OpenJS Foundation), 2026. link
  4. Joe Brockmeier. Stenberg: curl summer of bliss. LWN.net, 2026. link
  5. Daniel Stenberg. The end of the curl bug-bounty. daniel.haxx.se, 2026. link
  6. Socket. OpenJS Foundation Is Now a CNA for 40+ JavaScript Projects. Socket, 2025. link