AI Briefing
KOSign in

GNOME Maintainer Advocates for AI Vulnerability Scanning Amidst CVE Surge and Bug Bounty Closure

·2026.10.03 03:08

Key point

GNOME CVE counts rose approximately tenfold from 2021 to 2026, driven largely by AI-generated reports, prompting a policy shift to accept AI-assisted findings while managing false positives and ending the bug bounty program.

Details

AI-Driven Vulnerability Surge

GNOME maintainer Michael Catanzaro reports that CVE counts for GNOME projects have increased by an order of magnitude between 2021 and 2026. In 2021, there were 21 CVEs, whereas 2026 year-to-date (through roughly September 1) shows 141 CVEs, which normalizes to an estimated 188 for the full year. The primary driver of this increase is the widespread adoption of AI vulnerability scanning, which Catanzaro argues is essential for maintaining software quality in unsafe languages like C, C++, and Vala.

While AI reports were largely considered low-quality "slop" in 2025, their quality improved significantly in 2026. However, they still suffer from verbosity, severity exaggeration, and occasional hallucinations, such as fake stack traces. Despite these flaws, Catanzaro argues that banning AI-generated reports is impractical, as it would effectively ban most vulnerability reporting. Rewriting AI reports manually is also deemed unfeasible due to the sheer volume of bugs.

Bug Bounty Program Termination

The GNOME Bug Bounty Program, supported by the Sovereign Tech Agency and hosted on YesWeHack, closed in February 2026 due to the overwhelming burden of AI-generated reports. During its operation from June 2024 to February 2026, the program received 298 submissions and accepted 71, paying out €183,900 in total. The acceptance rate was low because financial incentives attracted many low-quality reports, whereas unpaid reports via standard trackers tended to be higher quality.

Key findings from the bounty program include:

  • libsoup: More vulnerabilities than expected, particularly related to DoS and request smuggling.
  • GLib: Integer overflows were a major issue, which could be largely prevented by using compiler flags like -Wconversion, -Wint-conversion, and -Wsign-compare, though most GNOME projects do not use them.

Red Hat and Human Audit Results

Red Hat commissioned AISLE Research to perform AI scans on GLib, resulting in 118 claimed vulnerabilities. However, 46 of these (40%) were false positives related to gobject-introspection typelib bugs, which are not security vulnerabilities because typelibs are inherently trusted. The remaining reports were high quality, and multiple CVEs are expected to be issued. This experiment demonstrated that Linux vendors can proactively find vulnerabilities without waiting for external researchers.

Additionally, Codean Labs conducted a human audit of Flatpak and xdg-desktop-portal under the Sovereign Tech Resilience program. They discovered critical issues, including a Flatpak sandbox escape via Yelp, which AI scans alone might have missed. This highlights that while AI is powerful, human expertise remains necessary for the most critical security findings.

Policy Recommendations and Rust Concerns

Catanzaro recommends that projects should not ban AI-generated reports solely based on their origin. Instead, maintainers should focus on verifying the findings. He also advises new developers to be cautious with AI-written code comments, which are often poor quality, and to avoid posting AI-generated comments as their own in issue trackers.

Regarding Rust, while memory safety reduces many vulnerabilities, it does not eliminate all risks. Supply chain security remains a significant concern, particularly with Cargo dependencies, where trojanized bundles pose a risk that may outweigh the benefits of memory safety. Consequently, Catanzaro does not currently recommend Rust for GNOME software development due to these supply chain risks.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.