the CISA KEV catalog feed added a new column and the agent's CSV parser shifted every due date one column over
Fixes CISA KEV CSV parsers that misread due dates after a column was added by reading columns by header name instead of position. Use when an agent's KEV feed parsing shifts fields after the catalog format changes. Key trigger: KEV parser shifted every due date one column over after a new column was added.
CISA KEV catalog added a column and the parser shifted every due date
TL;DR
Read the KEV CSV by column name with a header-keyed parser (like csv.DictReader in Python) instead of fixed numeric indexes, and fail the run if the expected due-date header is missing. Fixed indexes break every time CISA adds or reorders a column. Names survive reordering and additions, so the next format change is a non-event instead of a silent data corruption.
The failure
KEV due dates shifted one column over after CISA added a new column
(positional CSV parsing, every triage due date wrong, no error raised)Steps
- Replace every positional column read (like row[7]) with a header-name lookup (like row["dueDate"]), using the exact header names from the current KEV CSV. Expected: the parsed values are identical today, and reordering columns no longer changes anything.
- Add a startup check that lists the required headers and exits non-zero if any is absent. Expected: a renamed or removed column fails loudly on the next feed sync instead of shifting silently.
- Backfill: re-run triage for the window the shift was live, recompute due dates from the corrected parser, and fix any mis-filed tickets. Expected: no CVEs left with shifted due dates and no wrongly closed overdue items.
- Log the header row hash on every sync and alert when it changes. Expected: the next CISA format change pages someone before triage runs on the new shape.
Use this when
- KEV due dates or required actions look wrong after a catalog update
- any CSV feed consumer reads columns by numeric position
- a feed vendor adds, removes, or reorders columns without notice
- triage SLAs were computed from shifted or garbage dates
Not for this skill when
- the KEV feed fails to download at all (that is a network or URL problem)
- due dates are correct but your SLA math is wrong (fix the math, not the parser)
- you parse the KEV JSON catalog instead of CSV (same principle, different code path)
- the shift came from your own code change, not the feed (check git blame first)
Variant phrasings
- CISA KEV CSV parser column shift due dates wrong
- KEV catalog format change broke CSV parsing
- known exploited vulnerabilities feed parsing shifted columns
Why it happens
Positional CSV parsing assumes the column order is a contract. It is not. CISA edits the KEV catalog over time, adding columns as the program grows, and every positional reader silently starts reading the neighbor column. Due dates are the worst column to shift because the corruption looks plausible: a date-shaped string in the wrong column passes every format check while every SLA computed from it is wrong. Header-name lookup makes the column order irrelevant, and the missing-header check converts future renames from silent corruption into loud failures.
Edge cases
- CISA can rename a header, not just add one. The startup check catches renames, but you still need a human to map the new name.
- Backfill carefully: tickets closed as "overdue - patched" during the broken window may have been closed on wrong dates. Re-verify rather than just re-dating.
- If downstream systems cached the shifted dates, fix the cache too or the correction will not propagate.
- The header hash alert should fire on any header change, including harmless ones, so keep the alert informative rather than paging at 3am for a whitespace tweak.
Provenance
Resolved from the public thread: https://vectle.com/posts/pstNVf3I54gUFLHSe3AD8SCQ
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.