Anthropic's OSS Scanner Skips Human Review and the Public Advisory

Anthropic's OSS Scanner sends unreviewed, model-written bug reports to open-source maintainers and publishes nothing. Its disclosure pipeline has 516 of 6,157 findings patched and 584 identifiers issued, so many fixes will reach your dependencies with no CVE for your SCA tool to flag.

By Rajesh Beri·October 8, 2026·9 min read
Share:
A server-room desk with an open laptop showing a long list of email bug reports, beside a printed dependency list with several library names circled in red pen and a stack of unopened envelopes.

Illustration generated using AI

Anthropic's OSS Scanner sends model-written vulnerability reports to open-source maintainers with no human review and no public disclosure, so a security fix can land in a library you depend on without a CVE or advisory. If your patching runs on what your software composition analysis (SCA) tool flags, the bugs this program finds may never appear on your dashboard. Plan for that now, while the volume is still small.

Anthropic launched the Anthropic Cyber Mission on October 8, 2026 with two pieces: the free, opt-in OSS Scanner for critical open-source projects, and a Critical Infrastructure Defense Program (CIDP) that reaches power, water and transport operators through 11 partner firms. The scanner affects your vulnerability queue. CIDP will reach you as a partner engagement with no published terms.


What the OSS Scanner Actually Sends, and to Whom

The OSS Scanner is a free service that runs Anthropic's strongest models against enrolled open-source projects and emails each finding to the project's maintainers. Anthropic says it is inspired by Google's OSS-Fuzz, and each report carries a proof of concept, an explanation, and a suggested fix where one exists.

Enrollment is narrow. Per the scanner's own page, only core maintainers of "established projects with critical impact on infrastructure and user security" can sign up, the team verifies each maintainer by hand, and the criteria mirror OSS-Fuzz: exposure to untrusted input and the number of dependent projects. A maintainer enrolls by opening a pull request against the anthropics/oss-scanner repository with a project.yaml and a Dockerfile. The scan runs offline in an isolated sandbox after the build.

The departures from normal practice are spelled out plainly:

  1. No human checks the report before it goes out. Anthropic's announcement says reports "are model-generated and sent without human review" and may contain errors such as wrong severity ratings. It forecasts a true-positive rate above 90%.
  2. No public disclosure. The repository README says there is no 90-day disclosure period for these findings and that they will not be made public. A 90-day clock may start if a human later validates a report through Anthropic's separate coordinated disclosure process.
  3. Attribution is optional. Maintainers are asked, not required, to credit fixes with a line like "Discovered by Anthropic's OSS Scanner, as vulnerability ANT-2026-ABCD1234."

Compare that with the program it cites as its model. OSS-Fuzz's disclosure guidelines open every reported issue to the public after 90 days or once a fix ships, whichever is earlier. That public tracker is how downstream users learned what had been fixed. The OSS Scanner keeps the OSS-Fuzz enrollment model and drops the public record.

Why the Bottleneck Is Maintainers, Not Discovery

Anthropic can already find bugs far faster than open source can fix them. Its coordinated vulnerability disclosure dashboard, in a snapshot dated October 2, 2026, counts 29,439 candidate findings since November 1, 2025. External firms had reviewed 6,123 of them and confirmed 5,674, a 92.7% true-positive rate among those reviewed. Anthropic has disclosed 6,157 vulnerabilities across 591 projects. Maintainers have acknowledged 5,103. Only 516 are patched upstream, about 8% of what was disclosed.

The volume is climbing fast. When VulnCheck examined the ledger in June 2026, Anthropic had sent 1,596 findings out of 23,019 candidates, 1,129 of them unvalidated and sent at maintainers' request. By October 2 the disclosed count had nearly quadrupled.

The identifier gap matters most for your tooling. The October snapshot shows 584 identifiers issued against those 6,157 disclosures (219 CVEs and 365 GitHub security advisories, with some findings holding both). SCA scanners match your dependency versions against advisory databases. Unless your vendor runs its own research feed or reads ecosystem databases such as OSV, a fix with no CVE or GHSA produces no alert, so the upgrade it should trigger never reaches your backlog.

The strongest case for Anthropic's design is that unreviewed reports, sent to maintainers who asked for them, get fixes moving sooner than a queue that waits on six human triage firms. VulnCheck's analysis made the bottleneck concrete: at the pace it measured, working through the candidate backlog would take about 2.4 years. The same analysis noted that Claude had overestimated severity relative to third-party assessments and that the ledger showed no CVSS metrics. Speed at the maintainer's end does nothing for you if the fix ships silently.


The Last Time Free Reports Flooded a Project

Projects have already hit this wall with AI-generated reports, and one of them shut the door. The curl project ended its bug bounty at the end of January 2026. Daniel Stenberg said the goal was to "remove the incentive for people to submit crap and non-well researched reports to us. AI generated or not," after a week of seven submissions in which some identified bugs and none described a vulnerability.

Anthropic's design answers part of that complaint. Its reports carry a working proof of concept, enrollment is opt-in, and its policy says it will not send large volumes to a project without agreeing on a pace the maintainer can sustain. Volume is still the problem it cannot fix for the maintainer. An opted-in project run by a few volunteers will triage a batch of valid findings in some order, and nothing obliges it to file a CVE for each one.

Your fallback used to be the National Vulnerability Database, and it has stepped back. On April 15, 2026, NIST said it would enrich only prioritized CVEs: those in CISA's Known Exploited Vulnerabilities catalog, software used by the federal government, and critical software under Executive Order 14028. Everything published before March 1, 2026 that was still waiting moved to "Not Scheduled." CVE submissions rose 263% from 2020 to 2025, by NIST's count. Even the vulnerabilities that do get a CVE now often arrive without the product data your scanner needs to match them.

What CIDP Offers Critical Infrastructure, and What It Leaves Out

The Critical Infrastructure Defense Program brings frontier Claude models, on-site engineers and threat research to security providers that protect operational technology. Operators do not sign up directly. Anthropic's interest form is for companies that build security products or services for critical infrastructure, and the founding partners are Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC and Rockwell Automation.

The announcement names no price, no specific model, and no data-handling terms for partner deployments. That matters in OT, where the data a partner would feed Claude can include network captures, asset inventories and controller configurations for the kind of environment that CISA's AA26-231A advisory showed attackers targeting with AI-written scripts for Siemens S7 controllers.

Anthropic's own cyber programs show why the terms are worth asking for in writing. Two days earlier, the expanded Cyber Verification Program traded wider access to cyber capabilities for log retention. A CIDP engagement could carry a similar trade, and the announcement says nothing either way.

If you sell products into the EU, the clock is already running on your side. Since September 11, 2026, the Cyber Resilience Act requires manufacturers to send an early warning within 24 hours of learning that a vulnerability in their product is being actively exploited, a full notification within 72 hours, and a final report within 14 days of a fix. Open-source stewards do not take on reporting duties until December 11, 2027. Until then, the obligation for a bug in a bundled library sits with you.


What to Do About It

The work is to stop treating "no CVE" as "nothing to patch" for the libraries most likely to be scanned.

This Week:

  1. List your 30 most exposed open-source dependencies. Start with the parsers, TLS, compression and image libraries that handle untrusted input in internet-facing services. Those match the OSS Scanner's enrollment criteria, so they are where unpublicized fixes are most likely to land.
  2. Check which of them have enrolled. Watch the open and merged enrollment pull requests in the oss-scanner repository and flag any project on your list.
  3. Search upstream commit logs for "ANT-2026-". Anthropic asks maintainers to cite that identifier. Where it appears in a commit without a matching advisory, you have found a fix your SCA tool cannot see.

This Month:

  1. Ask your SCA vendor one question in writing: does the product flag security fixes that have no CVE or GHSA, and how? If the answer is no, add those flagged dependencies to a scheduled upgrade lane that takes every patch release, CVE or not.
  2. Add a second enrichment source to your vulnerability pipeline. With NVD enriching only prioritized CVEs, a single-source feed now leaves gaps for most libraries.
  3. If you maintain an open-source project your business depends on, decide whether to enroll. Enroll only if you can staff the triage. Anthropic says the service is meant for projects that already handle verified high and critical reports.

Before You Sign a CIDP Engagement:

  1. Get the model, the processing region, the retention period and the training terms in the contract. The announcement publishes none of them.
  2. Map CIDP findings to your CRA clock. Decide who owns the 24-hour early warning if a partner's Claude-assisted analysis is the first to show active exploitation in a product you ship.

The Bigger Picture

AI vulnerability discovery is following the arc fuzzing took, at a faster pace. OSS-Fuzz had helped find more than 10,000 vulnerabilities across roughly 1,000 projects by August 2023. Anthropic has disclosed 6,157 in under a year. The White House built Gold Eagle as a clearinghouse for exactly this kind of volume, and Anthropic now supports it and Akrites, while funding the Python Software Foundation, OpenSSF and Alpha-Omega through the Linux Foundation, and the Apache Software Foundation.

What fuzzing had and this fast track lacks is a public record that tells downstream users a fix happened. The vendors racing into this space, from OpenAI's Patch the Planet sprint to Codex Security Cloud's continuous scanning, will generate more fixes than advisories. A patch program keyed only to CVEs will miss the fixes that Claude and its rivals find and that maintainers ship quietly.

Run the "ANT-2026-" search against your top 30 dependencies before your next patch cycle.

Continue Reading

Share:

Frequently Asked Questions

What is Anthropic's OSS Scanner?

A free, opt-in service launched October 8, 2026 that runs Anthropic's strongest models against enrolled critical open-source projects and emails maintainers each finding with a proof of concept and a suggested fix. Only verified core maintainers of high-impact projects can enroll.

Are OSS Scanner findings reviewed by a human or made public?

No. Anthropic says reports are model-generated and sent without human review, with a forecast true-positive rate above 90%. The repository says there is no 90-day disclosure period and findings will not be made public unless a human later validates them through Anthropic's coordinated disclosure process.

Why might my SCA tool miss vulnerabilities Anthropic finds?

SCA tools alert on CVE or GitHub advisory identifiers. Anthropic's dashboard on October 2, 2026 showed 6,157 disclosed vulnerabilities but only 584 identifiers issued, and OSS Scanner findings are not published, so a fix can ship upstream with nothing for your scanner to match.

Can a utility or manufacturer join Anthropic's Critical Infrastructure Defense Program directly?

Not as announced. The interest form is for companies that build security products or services for critical infrastructure. Operators reach it through the 11 founding partners, and the announcement names no price, model or data-handling terms.

What should a security team do this week?

List your 30 most exposed open-source dependencies, check whether they have enrolled in the oss-scanner repository, and search their commit logs for the ANT-2026- identifier Anthropic asks maintainers to cite. A match without an advisory is a fix your scanner cannot see.

Newsletter

Stay Ahead of the Curve

Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.

Subscribe