Skip to content

About

A measurement of how often public vulnerability records change after people have acted on them.

Who

Patch Drift is built and run by one person, the maintainer of this repository. It is built independently; the author works at GreyNoise; no GreyNoise data is used. Every figure is read from the public git histories of the CVE catalog, CISA's KEV list and the GitHub Advisory Database, and nothing else.

Why

A CVE record names the version that fixes a flaw. A team reads it, patches to that version, closes the ticket. Then the record is edited: the fix version moves, a product is added, the score changes, CISA lists it. No notification from the catalog reopens the ticket. This site measures how often that happens, shows each change beside the commit it came from, and lets you check the records you closed.

How to cite

Name the snapshot: every figure on this site is computed from one dated file, and a later refresh can move it.

Patch Drift, snapshot 2026-09-07 (catalog commit 1f78fd2580c1), https://patchdrift.io

A figure and the date it was taken, together, never the figure alone. The method, every refusal class and the changelog of method changes are on the method page.

Contact

A finding you believe is wrong: dispute it, and it is re-examined against the catalog's own history. Anything else: hello@patchdrift.io.

Licence

The code is MIT; the code repository is private. The figures derived here are CC0: take them, with the snapshot date, and a link back matters more than credit because it puts the reader one click from the caveats that come with a number. The underlying records belong to their publishers and carry their own terms, which are reproduced in full below and bind you as they bind us.

Two conditions travel with any reuse: the three upstream licences in the next section, and the terms of use, which ask that the dataset is not repackaged and resold as a product of your own. When you quote a finding, quote what it is: A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.

Sources, licences and marks

Three public catalogs, read directly and nothing else consulted: no feed, no vendor bulletin, no scanner. The attributions below are published because two of these three licences require them.

SourceLicenceAttribution and notices
CVE Program catalog (cvelistV5)CVE Program Terms of UseCopyright (c) 1999-2026, The MITRE Corporation. CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation.
CISA Known Exploited Vulnerabilities catalogCreative Commons Zero 1.0 (CC0 1.0)A work of the U.S. Government, distributed under CC0 1.0. Use of the information does not authorize you to use the CISA Logo or DHS Seal, nor should such use be interpreted as an endorsement by CISA or DHS.
GitHub Advisory DatabaseCreative Commons Attribution 4.0 (CC-BY-4.0)Advisory data from the GitHub Advisory Database, used under CC-BY-4.0. GitHub states the attribution term is fulfilled by linking to the database or to the records used.

The CVE Program licence, reproduced

The CVE Program's grant is conditional on reproducing MITRE's copyright designation and the licence itself in any copy, so both are published here rather than summarised.

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

MITRE disclaims all warranties in the CVE data, express or implied, including any warranty that use of the information will not infringe any rights and any implied warranty of merchantability or fitness for a particular purpose. The full text is at cve.org/Legal/TermsOfUse.

Advisory data, and the link the licence asks for

Advisory findings are derived from the GitHub Advisory Database, used under CC-BY-4.0. GitHub states that the attribution term is satisfied by linking to the database, or to the individual records used, and that link is carried in the footer of every page as well as here.

Trademarks, and who we are not

All vendor, product and organisation names are the trademarks of their respective owners and are used here nominatively: to identify the records in which they appear, and for no other purpose.

CVE is a trademark and the CVE logo is a registered trademark of The MITRE Corporation. Use of the CISA KEV data does not authorise use of the CISA logo or the DHS seal and is not an endorsement by CISA or DHS, and no such use is made here. GitHub is a trademark of GitHub, Inc. No logo, seal or branding belonging to any of them is reproduced on this site.

This site is an independent project. It is not affiliated with, endorsed by, sponsored by, or approved by The MITRE Corporation, the CVE Program, CISA, the U.S. Department of Homeland Security, GitHub, or any vendor, publisher or CNA (CVE Numbering Authority) named anywhere on it.

What a finding is not

Nothing here is professional, security, legal or compliance advice, and nothing here is a substitute for the vendor's own advisory or for a scanner. It reports what a published record said and what it says now. It does not know what you run, and it cannot tell you whether you are exposed.

If your organisation is named anywhere on this site, you have a standing right of reply that does not depend on us being wrong. The corrections policy and the right of reply →