GitHub Releases – yadavnikhil17102004/CVE-Intel, EPSS Enrichment Data Quality Regression, CVE-Intel (Medium) -DC-Oct2026-2740

Listen to this Post

CVE-Intel is a security intelligence pipeline that maps Common Vulnerabilities and Exposures (CVEs) to publicly available GitHub exploit and proof-of-concept repositories. The project enriches this mapping with data from the National Vulnerability Database (NVD) and the CISA Known Exploited Vulnerabilities (KEV) catalog. A critical component of this enrichment is the Exploit Prediction Scoring System (EPSS), which provides probabilistic scores indicating the likelihood that a CVE will be exploited in the wild. The EPSS API is maintained by FIRST (Forum of Incident Response and Security Teams). In early 2026, FIRST migrated its EPSS API endpoint from its previous location to a new path: /data/v1/epss. The CVE-Intel pipeline relied on the old endpoint to fetch EPSS scores for each CVE in its dataset. Because the pipeline did not implement automatic endpoint discovery or failover, the migration caused the EPSS enrichment step to silently return zero records. This silent failure meant that the pipeline continued to generate datasets, but without any EPSS scores attached. As a result, downstream consumers of the intelligence data would see CVEs with missing or default EPSS values, leading to incorrect prioritization. The regression was not immediately detected because the pipeline lacked coverage reporting and validation gates. The v1.1.0 release of CVE-Intel addresses this by updating the EPSS client to use the new `/data/v1/epss` endpoint, regenerating all EPSS-enriched datasets, and adding automated validation via a new `validate.go` module. The release also introduces CI quality gates that check schema conformance, KEV matching, EPSS presence, and year-scoped dataset integrity. Additionally, a scraper fail-fast protection was added to halt the pipeline if EPSS enrichment returns zero records, preventing silent data-quality regressions. The validation summary for v1.1.0 shows 177,181 CVEs processed, 177,181 NVD matches, 1,035 KEV matches, 175,683 EPSS matches, and an EPSS coverage of 99.15%. This incident highlights the importance of resilience against upstream API changes and the need for automated safeguards in security intelligence pipelines.

DailyCVE Form:

Platform: GitHub Releases
Version: v1.1.0
Vulnerability: EPSS enrichment failure
Severity: Medium
date: 2026-07-26

Prediction: 2026-08-02

What Undercode Say:

Check EPSS coverage in the generated dataset
jq '[.cves[] | select(.epss_score != null)] | length' cve-intel.json
Expected output for v1.1.0: 175683
Run automated validation
go run validate.go --dataset cve-intel.json --schema nvd-schema.json --kev kev.json --epss epss.json
The validator checks schema, KEV, EPSS, and year-scoped integrity
// validate.go excerpt: fail-fast when EPSS returns zero records
func ValidateEPSS(records []EPSSRecord) error {
if len(records) == 0 {
return fmt.Errorf("EPSS enrichment returned zero records: pipeline halted")
}
return nil
}

How Exploit: (Educational Purposes!)

An attacker could exploit the silent EPSS enrichment failure by injecting malicious CVEs into the dataset with artificially low EPSS scores. Since the pipeline did not validate EPSS presence, these CVEs would appear to be low priority, causing defenders to deprioritize patching. The attacker could then exploit those CVEs before defenders react. This attack requires the ability to influence the upstream EPSS data source or the pipeline’s API endpoint. In a real-world scenario, an attacker who compromises the EPSS API response could return empty data, triggering the silent failure. The v1.1.0 fail-fast mechanism prevents this by halting the pipeline when zero records are returned.

Protection: from this CVE

  • Update to CVE-Intel v1.1.0 or later.
  • Ensure the EPSS client uses the `/data/v1/epss` endpoint.
  • Enable the `validate.go` automated dataset validation.
  • Activate CI quality gates for schema, KEV, EPSS, and year-scoped datasets.
  • Monitor EPSS coverage; alert if coverage drops below 99%.
  • Implement fail-fast protection to stop the pipeline on zero EPSS records.

Impact:

  • Silent data-quality regression in EPSS enrichment.
  • Missing EPSS scores for 1,498 CVEs (177,181 total minus 175,683 matched).
  • Incorrect prioritization of vulnerabilities due to absent or default EPSS values.
  • Potential delay in patching critical vulnerabilities.
  • Loss of trust in the intelligence pipeline’s data integrity.
  • Operational blindness without coverage reporting.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top