STUPID-2026-0049

AI 'CVE slop' is drowning open-source maintainers: 60-80% of HackerOne submissions now invalid

2.5low
March 10, 2026Verified
  1. Instruction given

    Generate and submit security vulnerability reports to open-source projects.

  2. Expected behavior

    Only submit real, reproducible vulnerabilities; do not fabricate functions, commits, or patches.

  3. Actual behavior

    Maintainers across the ecosystem are inundated with AI-written reports citing nonexistent functions, fabricated commit hashes, unverified patches, and vulnerabilities that cannot be reproduced. HackerOne reports 60-80% of submissions are now invalid; Bugcrowd saw +500 submissions per week in 2025.

  4. Damage

    Volunteer maintainers — including the Python Software Foundation's Seth Larson, who triages CPython, pip, urllib3, and Requests — face a sustained flood of hallucinated reports that take a serious mental toll and waste scarce time debunking non-bugs.

Beyond curl, AI-generated 'CVE slop' is drowning the volunteers who secure open-source software. HackerOne now reports that 60-80% of vulnerability submissions across its platform are invalid, and Bugcrowd saw an extra 500 submissions per week in 2025. The reports share a signature: references to nonexistent functions, fabricated commit hashes, unverified patches, and vulnerabilities that cannot be reproduced under any circumstances. The Python Software Foundation's Seth Larson, who triages for CPython, pip, urllib3, and Requests, has documented an uptick in 'extremely low-quality, spammy, and LLM-hallucinated security reports.' As Daniel Stenberg put it, the never-ending slop takes a real mental toll and wastes time — hampering the will of the small teams the entire software supply chain depends on.

Classification

Failure mode
Hallucination
Domain
Backend

Related incidents

Get told when an agent breaks something

We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.

This database is callable over MCP — query it from inside your agent.