Uploaded May 2026 | Updated September 2026, 1 hour ago
Pete Allor (CVE Board, US), Yogesh Mittal (Red Hat, IN)
The global vulnerability management ecosystem operates on a hidden "Vendor Bias"—the assumption that software producers have full visibility into downstream deployments and funded security teams. While this model works for commercial vendors, it breaks catastrophically when applied to Open Source Software (OSS). This paper exposes how this structural bias creates five critical failures in the OSS supply chain: the "Context Failure" (systemic risk inflation), the "Consensus Failure" (conflicting data from centralized authorities), the "Automation Failure" (AI-driven triage debt), the "Capacity Failure" (administrative exhaustion), and the "Resolution Failure" (the "Disputed" tag deadlock). We conclude that the technical ecosystem must mirror emerging policy innovations. We propose a "Federated Responsibility" framework that decouples risk assessment from upstream code maintenance, using the EU Cyber Resilience Act’s "Stewardship" model as a blueprint. By retiring the ambiguous "Disputed" tag in favor of a "Conditional" status, we can ensure enterprise-grade data quality while protecting the volunteer capacity that powers modern infrastructure.
---
Peter Allor is a Member of the CVE Board and a FIRST Liaison Member and occasional consultant while also participating in upstream security groups such as CVE, CVSS, and PSIRTs and supporting security for Open Source Software. He focuses on developing solutions that integrate the full spectrum of security operations within an organization’s domain in support of business.
Prior roles include the Senior Director, Product Security for Red Hat where he was instrumental in Red Hat's secure development and incident response programs. Senior Director for security at Honeywell, Cybersecurity Strategist at IBM and managing vulnerability and incident coordination at IBM for the IBM X-Force. Prior to IBM acquiring Internet Security Systems (ISS), Peter was the Special Assistant to the CEO of ISS for working National Infrastructure Advisory Council (NIAC) problem sets and assisted in forming the Information Technology - Sector Coordinating Council (IT-SCC) where he recently returned to the Executive Committee and Treasurer. As the former Operations Center Director, he ran the Information Technology - Information Sharing & Analysis Center (IT-ISAC) operations and brought coordination across the sector ISACs. Peter is a Member of the CVE Board, a former member Board of Director of the Forum of Incident Response and Security Teams (FIRST) and its Chief Financial Officer for FIRST. Peter was President to the Industry Consortium for Advancement of Security on the Internet (ICASI) and an Executive Committee Member of the IT Sector Coordinating Council (IT-SCC). A former Commissioner for the CSIS Cybersecurity Commission for the 44th Presidency, he assisted in developing recommendations for the Public and Private Sectors to work collaboratively on Cyber Security.
Peter is a retired Lieutenant Colonel from the US Army. He has Masters Degree from the University of Phoenix, a BS in Business Administration from Rollins College and is a Graduate of the US Army Command & General Staff College.
Yogesh Mittal is a PSIRT Manager at Red Hat, where he orchestrates strategic initiatives at the intersection of enterprise security and open source supply chain health. He oversaw Red Hat’s elevation to both CVE Program Root and CNA of Last Resort (CNA-LR) status. As a member of the CVE Program Roots Council, Yogesh plays a central role in evolving CNA Policy and operational standards, ensuring that governance frameworks are robust enough for global enterprises while remaining viable for decentralized communities.
Beyond policy, Yogesh bridges the gap between corporate governance and operational reality to align industry standards with the needs of the modern supply chain. He established a collaborative forum for Open Source CNAs and is dedicated to operationalizing "Federated Responsibility"—designing policy-backed frameworks that improve data quality without overburdening the volunteer workforce.
Pete Allor (CVE Board, US), Yogesh Mittal (Red Hat, IN)
The global vulnerability management ecosystem operates on a hidden "Vendor Bias"—the assumption that software producers have full visibility into downstream deployments and funded security teams. While this model works for commercial vendors, it breaks catastrophically when applied to Open Source Software (OSS). This paper exposes how this structural bias creates five critical failures in the OSS supply chain: the "Context Failure" (systemic risk inflation), the "Consensus Failure" (conflicting data from centralized authorities), the "Automation Failure" (AI-driven triage debt), the "Capacity Failure" (administrative exhaustion), and the "Resolution Failure" (the "Disputed" tag deadlock). We conclude that the technical ecosystem must mirror emerging policy innovations. We propose a "Federated Responsibility" framework that decouples risk assessment from upstream code maintenance, using the EU Cyber Resilience Act’s "Stewardship" model as a blueprint. By retiring the ambiguous "Disputed" tag in favor of a "Conditional" status, we can ensure enterprise-grade data quality while protecting the volunteer capacity that powers modern infrastructure.
---
Peter Allor is a Member of the CVE Board and a FIRST Liaison Member and occasional consultant while also participating in upstream security groups such as CVE, CVSS, and PSIRTs and supporting security for Open Source Software. He focuses on developing solutions that integrate the full spectrum of security operations within an organization’s domain in support of business.
Prior roles include the Senior Director, Product Security for Red Hat where he was instrumental in Red Hat's secure development and incident response programs. Senior Director for security at Honeywell, Cybersecurity Strategist at IBM and managing vulnerability and incident coordination at IBM for the IBM X-Force. Prior to IBM acquiring Internet Security Systems (ISS), Peter was the Special Assistant to the CEO of ISS for working National Infrastructure Advisory Council (NIAC) problem sets and assisted in forming the Information Technology - Sector Coordinating Council (IT-SCC) where he recently returned to the Executive Committee and Treasurer. As the former Operations Center Director, he ran the Information Technology - Information Sharing & Analysis Center (IT-ISAC) operations and brought coordination across the sector ISACs. Peter is a Member of the CVE Board, a former member Board of Director of the Forum of Incident Response and Security Teams (FIRST) and its Chief Financial Officer for FIRST. Peter was President to the Industry Consortium for Advancement of Security on the Internet (ICASI) and an Executive Committee Member of the IT Sector Coordinating Council (IT-SCC). A former Commissioner for the CSIS Cybersecurity Commission for the 44th Presidency, he assisted in developing recommendations for the Public and Private Sectors to work collaboratively on Cyber Security.
Peter is a retired Lieutenant Colonel from the US Army. He has Masters Degree from the University of Phoenix, a BS in Business Administration from Rollins College and is a Graduate of the US Army Command & General Staff College.
Yogesh Mittal is a PSIRT Manager at Red Hat, where he orchestrates strategic initiatives at the intersection of enterprise security and open source supply chain health. He oversaw Red Hat’s elevation to both CVE Program Root and CNA of Last Resort (CNA-LR) status. As a member of the CVE Program Roots Council, Yogesh plays a central role in evolving CNA Policy and operational standards, ensuring that governance frameworks are robust enough for global enterprises while remaining viable for decentralized communities.
Beyond policy, Yogesh bridges the gap between corporate governance and operational reality to align industry standards with the needs of the modern supply chain. He established a collaborative forum for Open Source CNAs and is dedicated to operationalizing "Federated Responsibility"—designing policy-backed frameworks that improve data quality without overburdening the volunteer workforce.










