# NVD merged two CVEs and the backlog has duplicate tickets

## TL;DR

Watch for NVD merge and reject events (cveTags markers, or one CVE ID disappearing while its description moves to another), and on a merge close the duplicate ticket as merged into the surviving CVE ID. Keep an alias map of merged IDs that the triage loop consults before filing, so future scans file under the survivor directly. Expected: one ticket per underlying bug, and no new duplicates from merged IDs.

## The failure

```text
two open tickets for CVE-A and CVE-B after NVD merged them into a single entry
(agent kept triaging both IDs as independent live CVEs)
```

## Steps

1. Build the alias map from NVD cveTags: rejected and disputed markers, plus merge notices where one ID's content moves to another. Expected: a table mapping every dead ID to its surviving ID.

2. Consult the alias map before filing: if the incoming CVE ID has an alias, file under the surviving ID. Expected: scans that surface the old ID open or update the survivor's ticket, never a new one.

3. Sweep the backlog for ID pairs that are both open on the same package and check them against the alias map. Expected: each merged pair collapses to a single ticket with a note recording the merge.

4. On future NVD syncs, diff the ID set against the previous sync and flag disappeared IDs for alias-map review. Expected: the next merge is caught on the first sync, not discovered months later.

## Use this when

- two tickets exist for CVEs that NVD merged or rejected
- the backlog grows with duplicate-looking tickets on the same package
- the agent treats every CVE ID as permanently independent
- NVD cveTags are ignored by your triage pipeline

## Not for this skill when

- the two CVEs are genuinely distinct bugs (verify before merging tickets)
- duplicates come from two scanners using different identifier schemes (normalize identifiers first)
- the duplicate tickets are for different packages or versions (those may be real)
- NVD has not actually merged anything and the IDs are both live

## Variant phrasings

- NVD CVE merged duplicate tickets in backlog
- rejected CVE still has open ticket
- two CVE IDs same vulnerability duplicate triage

## Why it happens

CVE IDs are not permanent. NVD merges duplicate assignments and rejects erroneous ones, but triage pipelines treat every ID they have ever seen as an independent live vulnerability. When CVE-B is merged into CVE-A, the pipeline keeps both tickets open because nothing told it they are the same bug now. The cveTags field exists precisely to signal this, and pipelines that ignore it accumulate ghost tickets that waste triage time and distort metrics.

## Edge cases

- A rejected CVE can be re-issued under a new ID for the same bug. The alias map must also reopen or link the old closed ticket, or the re-issued CVE looks brand new.
- Disputed tags are not merges. Do not auto-close disputed CVEs; route them to a human with the dispute context.
- Merging tickets loses history if done carelessly. Keep both IDs referenced on the surviving ticket so future searches find it.
- Scanners cache old CVE IDs. A scanner that still reports the dead ID needs the alias map applied at ingest, not just at filing time.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_th9dVnlrniQku61aW5nQMQ
