Open Source Conference Luxembourg

Digital Sovereignty Starts with Vulnerability Data

Digital sovereignty is often discussed in terms of cloud infrastructure, data hosting, or dependence on large technology providers. But there is a more uncomfortable question when it comes to cybersecurity: who owns vulnerability data?

Who controls the infrastructure, identifiers, databases, enrichment, and models that we rely on to understand vulnerabilities? Organizations such as MITRE, CISA and CVE Program provide critical public infrastructure for the cybersecurity ecosystem, but how much of our vulnerability intelligence ultimately depends on external organizations and services?

Vulnerability information is a fundamental building block of cybersecurity, yet organizations increasingly depend on external platforms, proprietary databases, closed scoring systems, and AI services to collect, enrich, and interpret it.

This talk explores what digital sovereignty can mean for vulnerability intelligence. Using the open-source Vulnerability-Lookup ecosystem as a case study, we will look at open vulnerability data, GCVE, decentralized sources, and open AI models and datasets developed with VulnTrain. The goal is to examine what it takes to build a security intelligence stack that can be independently operated, understood, reproduced, and extended.

The central question is simple: can we build vulnerability intelligence that we can actually own?


Vulnerability data is critical infrastructure for cybersecurity. Security teams use it to identify affected software, prioritize remediation, understand exploitation, and make decisions about risk. Yet the infrastructure used to collect and process this information is often fragmented and increasingly dependent on external services.

This talk takes vulnerability intelligence as a concrete case study for exploring digital sovereignty.

We will start with the data itself. Vulnerability-Lookup aggregates information from a large and growing ecosystem of open sources, including CVE, GHSA, OSV, CSAF, CNVD and other vulnerability databases, as well as security observations from sources such as MISP, Nuclei, Exploit-DB, GitHub, Mastodon, Bluesky and Telegram. This provides a foundation for building vulnerability intelligence without relying on a single proprietary platform.

We will then look at GCVE and the question of vulnerability identifiers. Who defines the identity of a vulnerability? Can vulnerability identification itself be part of an open and sovereign security ecosystem? And who funds the infrastructure on which the global vulnerability ecosystem depends? In the case of the CVE Program, the answer ultimately leads back to the U.S. government—not Europe.

The next layer is AI. With VulnTrain, vulnerability data can be transformed into open datasets and models capable of tasks such as predicting CWE classifications, extracting CVSS-related characteristics, and mapping vulnerabilities to MITRE ATT&CK techniques. This raises another aspect of sovereignty: having open data is useful, but what happens when the intelligence layer depends on closed AI models and proprietary inference services?

Finally, we will look at decentralized sources and the role of the Fediverse and other distributed platforms as potential sensors for vulnerability intelligence. Projects such as FediVuln and TARDISsight explore how these observations can be collected, correlated, and used to understand how vulnerabilities emerge and spread.

Rather than presenting a single product, the talk will use these projects to illustrate a broader architecture:

open data → open identifiers → open infrastructure → open models → open intelligence

The goal is to show that digital sovereignty in cybersecurity is not only about where our systems run. It is also about whether we can access, understand, process, reproduce, and ultimately control the security intelligence on which those systems depend.

Cédric Bonhomme

Cédric Bonhomme is a computer scientist with a strong focus on cybersecurity, privacy, and open-source software. From 2010 to 2017, he worked as an R&D Engineer specializing in Multi-Agent Systems and cybersecurity. Since 2017, he has been part of CIRCL (Computer Incident Response Center Luxembourg), contributing to CSIRT operations and developing open-source security tools and infrastructure.

He is the lead developer of Vulnerability-Lookup, an open-source platform for vulnerability intelligence, and works on vulnerability data, security automation, and AI/ML applied to cybersecurity. His work also includes GCVE, open vulnerability identifiers, and VulnTrain, a collection of open datasets and models for vulnerability analysis.