Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

CVE does cover "pre-release" software, part of the argument being you can't simply label something as "beta" and escape CVE coverage especially if millions of people are using it (Google's Chrome web browser was a good example of this). For example:

https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=prereleases



Sure, but Donenfield has specifically declared that CVEs not be issued for "pre-release" Wireguard components[1]:

> Current snapshots are generally versioned "0.0.YYYYMMDD" or "0.0.V", but these should not be considered real releases and they may contain security quirks (which would not be eligible for CVEs, since this is pre-release snapshot software).

[1]: https://www.wireguard.com/


Also to reiterate: "which would not be eligible for CVEs, since this is pre-release snapshot software" is not correct. It's usually correct, but not 100%.


Yeah and he's not the boss of CVE. If someone wanted a CVE for wireguard I'd be happy to help them get one.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: