Dispute a finding
If a finding is wrong, say so and it moves. This page is also the route for a reply, a legal notice, a privacy question and a security report about the site itself.
Last updated 2026-09-04.
If your organisation is named here
If your organisation is named anywhere on this site and you want to answer what a page says, send us the answer and we will publish it beside the finding, whether or not we agree with it. You do not have to show us a mistake first.
Context we would publish gladly: that the edit was a correction the programme asked for, that a range was restructured rather than widened, that a second advisory superseded the first, that a product line was renumbered. Any of those changes what a reader should conclude, and none requires our agreement.
A change shown here is a change to a public record, evidenced by a commit anyone can read in the publisher's own history. It is not an assertion of wrongdoing, negligence or bad faith by any publisher or vendor, not evidence that any fix was incomplete, and not a statement about anyone's systems.
Where to send it
- Or email security@patchdrift.io. Anonymous reports are fine.
Corrections are logged, with the headline figure before and after, on the method page.
The corrections policy
Four statements, published so they can be held against us.
- Every finding on this site is derived mechanically, by comparing a record's published state against its current state in the publisher's own git history. No finding is written, reviewed or approved by a person before it appears.
- Mechanical derivation gets things wrong. Every false-positive class this site refuses was found by shipping a wrong result first, and there is very likely another one we have not caught.
- A dispute is answered against the commit pair, not against our opinion. Pull the record at the commit the finding names and at the state it was published in; if those two blobs do not show what we say they show, the finding is wrong and we withdraw it.
- An upheld dispute is fixed in the classifier rather than in an exception list, so one correction moves every affected record and the published totals with it, and the change is written into the method changelog with the headline figure before and after. A correction cannot be made silently.
The refusal classes on the method page are what that policy has produced so far: each exists because a wrong result was published and caught, and each is tested so the same wrong result cannot come back.
Disagreeing with a finding is not the same as showing it wrong. If the record did change and you think the change was right, that is a reply and we publish it; if it did not change the way we say, that is a correction and we make it.
What settles it
Every finding names the upstream commit it came from, and the catalogs are public, so a dispute reduces to a commit pair: the record as first published, and the record at the commit we name. If we read them wrong, the evidence is in the pair.
- CVE records: CVEProject/cvelistV5
- CISA KEV: cisagov/kev-data
- GitHub advisories: github/advisory-database
Include, if you can:
- the CVE or GHSA id (CVE-2025-49407)
- the vendor and product as we render it
- what is wrong: the version never moved, the two versions are not comparable, a value is misread, or the wrong publisher is named
- what the record actually says, ideally at both commits
This page reflects the 2026-09-07 snapshot at catalog commit ed5547afbae2. The recipe for pulling any record at any commit is on the method page.
A problem with the site itself
Same routes. Please keep testing proportionate: this is a free public tool, so demonstrate a resource-exhaustion issue with arithmetic rather than by taking it down for everyone else. A machine-readable version of this page is at /.well-known/security.txt.
Use your own test inputs: saved reviews can hold private inventory and notes. Reviews stay in the browser; URLs can reach host logs; there are no accounts or cookies, and a watchlist is encoded in its own URL. Proportionate, good-faith testing reported to us is welcome and we will not pursue it.