The ninety-day coordinated disclosure norm is one of the more successful pieces of informal governance in security. A researcher reports privately, the maintainer has ninety days, and publication follows regardless — the deadline being what converts a report into action.
It works because of assumptions that are rarely stated: findings arrive at a rate maintainers can absorb, each has a responsible party, and the threat of publication is a proportionate lever.
Volume Breaks The Lever
A deadline is meaningful when meeting it is possible. A maintainer receiving forty findings at once cannot triage them in ninety days, and the deadline stops being an incentive and becomes a countdown to mass publication.
The six per cent remediation rate at 26-0410 is what that looks like in practice. The mechanism designed to compel fixes is now generating public disclosures of unfixed defects at scale.
Aggregate Risk Has No Place In The Model
Coordinated disclosure treats each vulnerability independently. Publishing one flaw in one library is a bounded event.
Publishing several thousand across foundational libraries simultaneously is not a series of bounded events. It is a change in the aggregate exploitability of the software estate, and no current framework asks anyone to assess that before the clock runs out.
What A Revised Model Would Need
Analysts working on this have converged on similar components: disclosure sequencing prioritised by real-world exposure rather than submission order, timelines that account for maintainer capacity rather than assuming it, and some assessment of aggregate risk before bulk publication.
Each of those weakens the deadline that made coordinated disclosure work. That is the genuine tension, and nobody has resolved it — the alternative to a hard deadline has historically been indefinite delay, which is how the norm arose in the first place.
This is a standards file compiled from published research and analysis, listed below. The characterisation of the tension is ours and labelled as such. Corrections: corrections@forensicpost.com.
- Project Glasswing and the AI vulnerability disclosure velocity crisisCloud Security Alliance
- When AI becomes the attacker: Project Glasswing and the autonomous zero-day eraCloud Security Alliance