NVD merged two CVE entries into one and the agent's backlog now has duplicate tickets for both IDs
Fixes duplicate tickets after NVD merges two CVE entries by watching for merge and reject events and filing under the surviving CVE ID via an alias map. Use when the backlog holds two open tickets for what turned out to be one bug. Key trigger: NVD merged two CVE entries and the backlog has duplicate tickets for both IDs.
NVD merged two CVEs and the backlog has duplicate tickets
TL;DR
Watch for NVD merge and reject events (cveTags markers, or one CVE ID disappearing while its description moves to another), and on a merge close the duplicate ticket as merged into the surviving CVE ID. Keep an alias map of merged IDs that the triage loop consults before filing, so future scans file under the survivor directly. Expected: one ticket per underlying bug, and no new duplicates from merged IDs.
The failure
two open tickets for CVE-A and CVE-B after NVD merged them into a single entry
(agent kept triaging both IDs as independent live CVEs)Steps
- Build the alias map from NVD cveTags: rejected and disputed markers, plus merge notices where one ID's content moves to another. Expected: a table mapping every dead ID to its surviving ID.
- Consult the alias map before filing: if the incoming CVE ID has an alias, file under the surviving ID. Expected: scans that surface the old ID open or update the survivor's ticket, never a new one.
- Sweep the backlog for ID pairs that are both open on the same package and check them against the alias map. Expected: each merged pair collapses to a single ticket with a note recording the merge.
- On future NVD syncs, diff the ID set against the previous sync and flag disappeared IDs for alias-map review. Expected: the next merge is caught on the first sync, not discovered months later.
Use this when
- two tickets exist for CVEs that NVD merged or rejected
- the backlog grows with duplicate-looking tickets on the same package
- the agent treats every CVE ID as permanently independent
- NVD cveTags are ignored by your triage pipeline
Not for this skill when
- the two CVEs are genuinely distinct bugs (verify before merging tickets)
- duplicates come from two scanners using different identifier schemes (normalize identifiers first)
- the duplicate tickets are for different packages or versions (those may be real)
- NVD has not actually merged anything and the IDs are both live
Variant phrasings
- NVD CVE merged duplicate tickets in backlog
- rejected CVE still has open ticket
- two CVE IDs same vulnerability duplicate triage
Why it happens
CVE IDs are not permanent. NVD merges duplicate assignments and rejects erroneous ones, but triage pipelines treat every ID they have ever seen as an independent live vulnerability. When CVE-B is merged into CVE-A, the pipeline keeps both tickets open because nothing told it they are the same bug now. The cveTags field exists precisely to signal this, and pipelines that ignore it accumulate ghost tickets that waste triage time and distort metrics.
Edge cases
- A rejected CVE can be re-issued under a new ID for the same bug. The alias map must also reopen or link the old closed ticket, or the re-issued CVE looks brand new.
- Disputed tags are not merges. Do not auto-close disputed CVEs; route them to a human with the dispute context.
- Merging tickets loses history if done carelessly. Keep both IDs referenced on the surviving ticket so future searches find it.
- Scanners cache old CVE IDs. A scanner that still reports the dead ID needs the alias map applied at ingest, not just at filing time.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_th9dVnlrniQku61aW5nQMQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.