Uploaded May 2026 | Updated September 2026, 1 hour ago
Alexandra Selldorff (Manifest Cyber, US)
Matching vulnerabilities to software components sounds straightforward: take a list of packages, take a list of CVEs, and connect the two. In reality, vulnerability matching is one of the most complex and error-prone parts of modern vulnerability management. The identifiers we rely on, such as CPEs and Package URLs (PURLs), are imperfect abstractions of real-world software, while vulnerability data sources often contain gaps, inconsistencies, and conflicting interpretations. This talk explores why vulnerability matching is such a nuanced problem. We’ll examine how CPEs struggle to model modern package ecosystems, how PURLs vary across languages and distributions, and how incomplete or mismatched metadata leads to false positives and missed vulnerabilities. We’ll also compare discrepancies across major data sources including NVD, CVE.org, OSV, and vendor advisories. Attendees will leave with practical techniques for investigating suspicious findings, verifying vulnerability matches, and reducing noise in scanner outputs. The session concludes with guidance on selecting and combining scanners, and proven workflows for managing false positives while maintaining trust in SBOMs and vulnerability reporting.
---
Lexi Selldorff is a Senior Engineering Manager at Manifest, leading work on SBOM vulnerability scanning. Previously, she was an Engineering Manager at Rula and a Forward Deployed Engineer at Palantir. She has built and operated software in highly regulated environments, including healthcare and government, and is passionate about delivering mission-critical systems quickly and securely. Lexi enjoys getting deep into data, and her work at Manifest focuses on the real-world challenges of vulnerability matching, package identification, and reducing noise in vulnerability management.
Alexandra Selldorff (Manifest Cyber, US)
Matching vulnerabilities to software components sounds straightforward: take a list of packages, take a list of CVEs, and connect the two. In reality, vulnerability matching is one of the most complex and error-prone parts of modern vulnerability management. The identifiers we rely on, such as CPEs and Package URLs (PURLs), are imperfect abstractions of real-world software, while vulnerability data sources often contain gaps, inconsistencies, and conflicting interpretations. This talk explores why vulnerability matching is such a nuanced problem. We’ll examine how CPEs struggle to model modern package ecosystems, how PURLs vary across languages and distributions, and how incomplete or mismatched metadata leads to false positives and missed vulnerabilities. We’ll also compare discrepancies across major data sources including NVD, CVE.org, OSV, and vendor advisories. Attendees will leave with practical techniques for investigating suspicious findings, verifying vulnerability matches, and reducing noise in scanner outputs. The session concludes with guidance on selecting and combining scanners, and proven workflows for managing false positives while maintaining trust in SBOMs and vulnerability reporting.
---
Lexi Selldorff is a Senior Engineering Manager at Manifest, leading work on SBOM vulnerability scanning. Previously, she was an Engineering Manager at Rula and a Forward Deployed Engineer at Palantir. She has built and operated software in highly regulated environments, including healthcare and government, and is passionate about delivering mission-critical systems quickly and securely. Lexi enjoys getting deep into data, and her work at Manifest focuses on the real-world challenges of vulnerability matching, package identification, and reducing noise in vulnerability management.










