Mind the Match: Why Vulnerability Matching Is Harder Than You Think @FIRSTdotorg
Mind the Match: Why Vulnerability Matching Is Harder Than You Think  @FIRSTdotorg
Uploaded May 2026 | Updated September 2026, 1 hour ago
Alexandra Selldorff (Manifest Cyber, US)

Matching vulnerabilities to software components sounds straightforward: take a list of packages, take a list of CVEs, and connect the two. In reality, vulnerability matching is one of the most complex and error-prone parts of modern vulnerability management. The identifiers we rely on, such as CPEs and Package URLs (PURLs), are imperfect abstractions of real-world software, while vulnerability data sources often contain gaps, inconsistencies, and conflicting interpretations. This talk explores why vulnerability matching is such a nuanced problem. We’ll examine how CPEs struggle to model modern package ecosystems, how PURLs vary across languages and distributions, and how incomplete or mismatched metadata leads to false positives and missed vulnerabilities. We’ll also compare discrepancies across major data sources including NVD, CVE.org, OSV, and vendor advisories. Attendees will leave with practical techniques for investigating suspicious findings, verifying vulnerability matches, and reducing noise in scanner outputs. The session concludes with guidance on selecting and combining scanners, and proven workflows for managing false positives while maintaining trust in SBOMs and vulnerability reporting.

---

Lexi Selldorff is a Senior Engineering Manager at Manifest, leading work on SBOM vulnerability scanning. Previously, she was an Engineering Manager at Rula and a Forward Deployed Engineer at Palantir. She has built and operated software in highly regulated environments, including healthcare and government, and is passionate about delivering mission-critical systems quickly and securely. Lexi enjoys getting deep into data, and her work at Manifest focuses on the real-world challenges of vulnerability matching, package identification, and reducing noise in vulnerability management.
Mind the Match: Why Vulnerability Matching Is Harder Than You ThinkOpenTide: From Raw Intelligence to Structured Threat-Informed DetectionsThe Vulnerability Ecosystem’s Vendor Bias — Exposed by Open SourceRouting Security for Enterprises: Secure Your Supply ChainEmbracing the Era of Transparency: Automating VEX Application for Scalable, Context-Aware SecurityAttack or Noise?: Tracking and Evaluating the Impact of Internet-Wide Survey ScannersAI Is Writing Your Bug Reports. Can You Tell?Dark Silicon: Unmasking GPU Threats in the Age of AIAxiomatic Events that Evolved Vulnerability DatabasesOrganizational Context Matters: Security Control Effectiveness on Vulnerabilities for PrioritizationNIST’s National Vulnerability Database Update and the Vulnerability Enrichment EcosystemDefeating Node.js Malware through API Tracing
FIRST |

Mind the Match: Why Vulnerability Matching Is Harder Than You Think

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER