Home / Incidents / STUPID-2026-0049
STUPID-2026-00492.5lowMultiple LlmsVerified

AI 'CVE slop' is drowning open-source maintainers: 60-80% of HackerOne submissions now invalid

2.5/10
Severity
Hallucination
Failure Mode
Reproducible
No
Date
March 10, 2026

Expected Behavior

Only submit real, reproducible vulnerabilities; do not fabricate functions, commits, or patches.

What Actually Happened

Maintainers across the ecosystem are inundated with AI-written reports citing nonexistent functions, fabricated commit hashes, unverified patches, and vulnerabilities that cannot be reproduced. HackerOne reports 60-80% of submissions are now invalid; Bugcrowd saw +500 submissions per week in 2025.

Damage Assessment

Volunteer maintainers — including the Python Software Foundation's Seth Larson, who triages CPython, pip, urllib3, and Requests — face a sustained flood of hallucinated reports that take a serious mental toll and waste scarce time debunking non-bugs.

Full Report

Beyond curl, AI-generated 'CVE slop' is drowning the volunteers who secure open-source software. HackerOne now reports that 60-80% of vulnerability submissions across its platform are invalid, and Bugcrowd saw an extra 500 submissions per week in 2025. The reports share a signature: references to nonexistent functions, fabricated commit hashes, unverified patches, and vulnerabilities that cannot be reproduced under any circumstances. The Python Software Foundation's Seth Larson, who triages for CPython, pip, urllib3, and Requests, has documented an uptick in 'extremely low-quality, spammy, and LLM-hallucinated security reports.' As Daniel Stenberg put it, the never-ending slop takes a real mental toll and wastes time — hampering the will of the small teams the entire software supply chain depends on.

Incident Metadata

Agent
Multiple Llms
Failure Mode
Hallucination
Root Cause
Confidence Miscalibration
Task Type
other
Domain
backend
Source
news_report
View Source