Chainguard gains authority to assign CVEs to qualifying Athena findings

Chainguard can now assign CVEs to qualifying Athena findings, including open source flaws fixed upstream without an identifier.

By · Published

Primary source: Chainguard via PR Newswire

Why it matters

Chainguard can give certain previously unnumbered flaws a CVE record that scanners can use. Its planned first disclosures will test the accuracy of those records and the path from finding to fix.

A close-up of a glowing, intricate digital software network with a subtle amber-lit anomaly, indicating a hidden flaw, on a high-resolution display.

Dan Lorenc (@lorenc_dan) has spent years building Chainguard to supply enterprises with hardened open source software. On September 22nd, Chainguard announced through PR Newswire that it had gained a different kind of responsibility: authority to assign CVE identifiers to qualifying vulnerabilities handled by its Athena coalition. The immediate target is a flaw that has already been fixed in a project's current code but remains unrecorded, leaving older versions harder for conventional vulnerability scanners to flag.

Lorenc knows the infrastructure on both sides of that problem. Before founding Chainguard in 2021 with Matt Moore, Ville Aikas, Kim Lewandowski and Scott Nichols, he worked on open source security and container tooling at Google. In Chainguard's founding announcement, he argued that secure software supply chains required changing how code is built and consumed, rather than adding security after deployment. The CNA authorization extends that thesis from shipping vetted software into documenting which other versions need attention.

A narrow authority with a large backlog

A CVE Numbering Authority can assign identifiers and publish records within its approved scope. Chainguard says its scope covers qualifying open source vulnerabilities processed through Athena: cases where maintainers fixed a flaw without an identifier, no maintainer remains to assign one, or no more specific CNA covers the project. Chainguard says it will defer to project maintainers and project-specific CNAs where they exist. Those limits matter. The designation does not give Chainguard blanket authority over open source vulnerabilities, and an assigned identifier does not prove that a proposed fix works.

The missing identifier creates a practical gap. An organization can be running an old, vulnerable release even though a newer release has quietly fixed the bug. Without a CVE record describing affected and fixed versions, scanners and compliance workflows that depend on those records have less to work with. Chainguard says its records will include version ranges and technical details intended to help teams assess exposure without treating every version of a package as vulnerable. Chief information security officer Quincy Castro described CNA status in the announcement as a way to communicate fixes in a "language" familiar to organizations and maintainers.

The authorization arrives ahead of a specific disclosure test. In a September 15th post, Lorenc said Athena planned to begin releasing about 50 findings on September 28th. He described the first group as lower-stakes "silent fixes": flaws corrected in current code, sometimes years earlier, without a CVE. Chainguard plans to publish patches for older versions, advisories specifying affected ranges, and patched builds for Chainguard Libraries customers. September 28th is a stated plan, not a completed release as of September 23rd.

Chainguard says Athena has processed more than 40,000 findings across more than 500 projects and produced more than 2,000 patches. These are company-reported measures of work at different stages, not 40,000 published vulnerabilities or 2,000 fixes adopted by upstream maintainers. Lorenc put the constraint plainly in his September post: "Generating fixes was never the bottleneck." Getting findings disclosed responsibly, and fixes into the software people actually run, is the harder test.

Disclosure is also distribution

Athena brings together organizations that can act at different points between discovery and remediation. Chainguard names Akamai, BNY, Cisco, Cloudflare, JPMorganChase, Kyndryl, Morgan Stanley and Upwind among its coalition members and mitigation partners. It says Akrites works with Athena on disclosure and durable upstream remediation. Chainguard's Athena page describes a process that pools vetted findings, prepares hardened builds before disclosure and gives network or security partners advance information to develop mitigations. Those are distinct steps; a CVE identifier alone does none of them.

There is a commercial reason for Chainguard to build that pipeline as well as a security reason. Lorenc wrote in July that joining the Athena partner program is free. His stated model charges submitters that impose disclosure restrictions, while Chainguard's customers receive fixes through its software products. More useful findings can improve the protection those products offer; a broadly usable CVE record can help the wider market recognize a flaw. That arrangement makes the quality of Chainguard's validation, coordination with maintainers and eventual upstream adoption consequential well beyond its customer base.

Chainguard has substantial capital behind that expansion. In April 2025, Lorenc announced a $356 million Series D led by Kleiner Perkins and IVP at a company-reported $3.5 billion valuation. He named Salesforce Ventures, Datadog Ventures and existing backers including Sequoia, Spark, Amplify, Redpoint and Lightspeed as participants. That was a 2025 funding event, not financing attached to this week's authorization.

The first disclosure batch should make Chainguard's approach easier to judge. The useful measure will be whether its records identify affected versions precisely enough for defenders to act, its patches hold up, and maintainers can work with the process. A CNA designation gives Lorenc's team a recognized way to publish an identifier. It leaves the work of getting a trustworthy fix into use where it has always been: with the people building, maintaining and running the software.

Reader comments

Conversation for this story loads after sign-in.