VulNow identifies verified vulnerabilities in your software supply chain an average of 10 days before they appear in public CVE feeds, before the attacker window opens. We call these Dark Matter Vulnerabilities™: security flaws that exist in production code, invisible to every CVE-based tool but exploitable by attackers.
The fix is in the code. The advisory is not. That gap (hours, days, or months wide) is where breaches happen and where CVE-based tools go blind.
Dark Matter Vulnerabilities™ are security flaws that exist in open source packages after a maintainer silently pushes a fix, but before any CVE or advisory is published. They are invisible to every scanner that relies on CVE feeds. Attackers can reverse-engineer the fix and begin exploiting unpatched systems immediately. Defenders have no signal, no patch notice, and no indication of exposure. VulNow detects these vulnerabilities in the pre-disclosure window and surfaces them as PreCVEs.
Maintainer discovers security-relevant bug in dependency
Fix pushed to repo. No CVE filed, no advisory issued
Prior versions remain vulnerable. CVE scanners show all-clear.
Attacker reverse-engineers patch, scans for exposed systems
Defenders finally receive signal, often weeks or months later
CVE records take an average of 40 days to publish after ID assignment. 80% of exploits are published before the corresponding CVE is officially released (Unit 42, 2024). 23.6% of CVEs added to CISA's KEV catalog were already being weaponized on or before the day the CVE was disclosed (VulnCheck, 2024).
A 16-day patching window against a 5-day exploitation window is not a security posture. VulNow moves the signal before the chasm begins.
Every detection below was confirmed by a subsequently published security advisory — a CVE record, a GitHub Security Advisory, or both. Roughly 85% arrived more than a full day before that advisory existed; the mean lead time across the set is approximately 10 days.
| # | Package | Ecosystem | Severity | Lead Time | Advisory Outcome |
|---|---|---|---|---|---|
| 1 | axios | npm | Medium | 154d 15h | GHSA + CVE |
| 2 | react-router | npm | Medium | 93d 17h | GHSA + CVE |
| 3 | authlib | PyPI | Medium | 90d 9h | GHSA + CVE |
| 4 | sqlparse | PyPI | High | 73d 4h | GHSA only |
| 5 | authlib | PyPI | Medium | 55d 21h | GHSA only |
| 6 | python-dotenv | PyPI | Medium | 50d 21h | GHSA + CVE |
| 7 | undici | npm | High | 48d 16h | GHSA + CVE |
| 8 | v8 | Source repo | High | 39d 6h | CVE only |
| 9 | pillow | PyPI | High | 37d 16h | GHSA + CVE |
| 10 | laravel/framework | Packagist | High | 28d 2h | GHSA only |
| 11 | ws | npm | High | 24d | GHSA only |
| 12 | markdown-it | npm | High | 22d 11h | GHSA only |
| 13 | cassandra-all | Maven | Medium | 20d 18h | GHSA + CVE |
| 14 | dompurify | npm | Critical | 20d 7h | GHSA only |
| 15 | symfony/symfony | Packagist | High | 20d 7h | GHSA only |
| 16 | shell-quote | npm | Critical | 17d 23h | GHSA + CVE |
| 17 | activemq-core | Maven | Critical | 17d 15h | GHSA + CVE |
| 18 | twig/twig | Packagist | Critical | 16d 8h | GHSA only |
| 19 | jdbi3-freemarker | Maven | Critical | 7d 15h | GHSA only |
Selected findings from a snapshot of 328 confirmed detections (late July 2026) · 97 packages · npm, PyPI, Packagist, Maven, Go, and container images
80% of exploits are published before the corresponding CVE is officially released, with an average lead of 23 days (Unit 42, State of Exploit Development, 2024).
CVEs added to CISA's Known Exploited Vulnerabilities catalog were already being weaponized on or before the day the CVE was publicly disclosed (VulnCheck, 2024).
Roughly 36% of VulNow's Q2 2026 confirmed findings resolved to a GitHub Security Advisory with no CVE record. For a CVE-keyed scanner, these vulnerabilities don't just arrive late — they don't exist.
The EU Cyber Resilience Act mandates that manufacturers of products with digital elements actively identify, document, and address vulnerabilities, including those not yet publicly disclosed. CVE-based tooling alone cannot satisfy this requirement.
VulNow's PreCVE intelligence directly addresses the CRA's requirements for proactive vulnerability handling, giving EU-regulated organizations a defensible, documented advantage over the silent fix window.
With hard deadlines in September 2026 and December 2027, organizations that have not established proactive vulnerability intelligence programs are already behind.
CRA Article 13 requires manufacturers to identify and document vulnerabilities including those discovered before public disclosure. PreCVEs satisfy this before the CVE exists.
CRA mandates software bill of materials transparency. VulNow enriches your SBOM data with real-time PreCVE risk signals your components carry before any CVE exists.
Standard CVE scoring underweights distribution scale. VulNow's severity is refined against real-world download and deployment data (Tier 2 plan), providing defensible risk classification for regulated product portfolios.
Whether you're protecting your own software supply chain or shipping next-generation security tooling, PreCVE intelligence opens new categories of detection.
Original research on software supply chain risk, PreCVE intelligence, and the data behind modern vulnerability management.
320+ confirmed PreCVE detections, a disclosure system that has publicly said it can't keep up, and VulNow's appointment as a CVE Numbering Authority.
VulNow B.V. today announced its formal appointment as a CVE Numbering Authority (CNA) under the ENISA CVE Root, authorizing the company to directly assign CVE identifiers to vulnerabilities surfaced by its predictive intelligence engine.
First full quarter of production PreCVE intelligence: 58 verified detections across 28 packages and 13.2 billion monthly downloads, with average lead time of 6.6 days.
A data-driven investigation into why 83% of supply chain attacks could have been prevented, and why the solution that already exists remains ignored.
Author of Software Supply Chain Security (O'Reilly). Former VP of Supply Chain Security at Schneider Electric (a €38B global enterprise), where she led product security and cyber resilience programs across complex international supply chains. Internationally recognized speaker and authority on vulnerability management, product risk, and EU regulatory compliance. Board director at Cybeats.
20+ years in security, cloud architecture, DevOps, and resilient infrastructure across regulated and mission-critical environments. Built and secured large-scale production systems in Banking and Fintech using AWS, Kubernetes, IaC, and CI/CD automation. Leads VulNow's technical platform, translating deep engineering expertise into scalable predictive vulnerability intelligence.
Join VulNow's Predictive Pilot Program. Receive live PreCVE detections for your dependency stack, or integrate our intelligence feed into your security platform.
Contact: info@vul.now · Netherlands-based · Serving most global markets