AI 'CVE slop' is drowning open-source maintainers: 60-80% of HackerOne submissions now invalid
2.5/10
Severity
Hallucination
Failure Mode
Reproducible
No
Date
March 10, 2026
Expected Behavior
Only submit real, reproducible vulnerabilities; do not fabricate functions, commits, or patches.
What Actually Happened
Maintainers across the ecosystem are inundated with AI-written reports citing nonexistent functions, fabricated commit hashes, unverified patches, and vulnerabilities that cannot be reproduced. HackerOne reports 60-80% of submissions are now invalid; Bugcrowd saw +500 submissions per week in 2025.
Damage Assessment
Volunteer maintainers — including the Python Software Foundation's Seth Larson, who triages CPython, pip, urllib3, and Requests — face a sustained flood of hallucinated reports that take a serious mental toll and waste scarce time debunking non-bugs.
Full Report
Beyond curl, AI-generated 'CVE slop' is drowning the volunteers who secure open-source software. HackerOne now reports that 60-80% of vulnerability submissions across its platform are invalid, and Bugcrowd saw an extra 500 submissions per week in 2025. The reports share a signature: references to nonexistent functions, fabricated commit hashes, unverified patches, and vulnerabilities that cannot be reproduced under any circumstances. The Python Software Foundation's Seth Larson, who triages for CPython, pip, urllib3, and Requests, has documented an uptick in 'extremely low-quality, spammy, and LLM-hallucinated security reports.' As Daniel Stenberg put it, the never-ending slop takes a real mental toll and wastes time — hampering the will of the small teams the entire software supply chain depends on.
Incident Metadata
- Agent
- Multiple Llms
- Failure Mode
- Hallucination
- Root Cause
- Confidence Miscalibration
- Task Type
- other
- Domain
- backend
- Source
- news_report