[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"glossary-cve::en":3,"gloss-cluster-cve::en":26,"gloss-next-cve::en":9},{"slug":4,"category":5,"name":6,"definition":7,"meta_desc":8,"faq":9,"schema_markup":9,"related":10},"cve","security","CVE (Common Vulnerabilities and Exposures)","A CVE identifier is a unique public reference for a specific security vulnerability in a specific product, in the form CVE-year-number. Its purpose is coordination rather than analysis: it gives vendors, scanners, distributions and defenders one unambiguous name for the same flaw, so an advisory, a patch note and a scanner finding can be matched to each other without guessing. Each entry describes the affected versions and links to the vendor's advisory. A CVE is usually accompanied by a severity score, and this is where teams most often go wrong. A base score describes the vulnerability in the abstract — how it can be reached, what it grants — but not whether your deployment is exposed. A critical-rated flaw in a code path your application never calls, in a container with no network exposure, may matter less than a medium-rated one on your public edge. Triage therefore has to combine the score with reachability, exposure and the presence of exploitation in the wild, and a policy that requires patching by score alone reliably produces both alert fatigue and misplaced urgency. Operationally, CVEs are how dependency scanning works: a software bill of materials lists what you ship, a scanner matches those components and versions against published identifiers, and the lockfile is what makes the answer exact. The recurring failure is not the initial scan but the ongoing one — a dependency that was clean when it was added and has a published CVE eighteen months later, with nobody watching.","A CVE is the public identifier for one vulnerability in one product — how scanners use it, and why patching by severity score alone misreads real exposure.",null,[11,14,17,20,23],{"slug":12,"name":13},"lockfile","Lockfile",{"slug":15,"name":16},"package-manager","Package Manager",{"slug":18,"name":19},"software-bill-of-materials","Software Bill of Materials (SBOM)",{"slug":21,"name":22},"supply-chain-security","Software Supply-Chain Security",{"slug":24,"name":25},"vulnerability-disclosure-policy","Vulnerability Disclosure Policy",[27,31,35,39,42,45,48,51,54,57,60,63],{"slug":28,"category":5,"name":29,"updated_at":30},"audit-log","Audit Log (Audit Trail)","2026-08-24T02:46:37+00:00",{"slug":32,"category":5,"name":33,"updated_at":34},"blast-radius","Blast Radius","2026-08-24T03:30:02+00:00",{"slug":36,"category":5,"name":37,"updated_at":38},"break-glass-access","Break-Glass Access","2026-08-24T02:46:38+00:00",{"slug":40,"category":5,"name":41,"updated_at":38},"bridge-letter","Bridge Letter",{"slug":43,"category":5,"name":44,"updated_at":38},"business-associate-agreement","Business Associate Agreement (BAA)",{"slug":46,"category":5,"name":47,"updated_at":30},"byok","Bring Your Own Key (BYOK)",{"slug":49,"category":5,"name":50,"updated_at":34},"data-classification","Data Classification",{"slug":52,"category":5,"name":53,"updated_at":38},"data-loss-prevention","Data Loss Prevention (DLP)",{"slug":55,"category":5,"name":56,"updated_at":38},"data-minimization","Data Minimization",{"slug":58,"category":5,"name":59,"updated_at":38},"data-poisoning","Data Poisoning",{"slug":61,"category":5,"name":62,"updated_at":38},"data-processing-agreement","Data Processing Agreement (DPA)",{"slug":64,"category":5,"name":65,"updated_at":30},"data-retention","Data Retention Policy"]