Feature Requests
New / Open / Unreviewed

Feature Request: Show CVE and CVSS for Security Updates

Currently, PatchMon shows when a package has a Security Update Available, but it would be very useful to also show the CVE and CVSS severity associated with that update.

For example:

PackageCVECVSSSeverityopensslCVE-2026-XXXX9.8CriticalopensshCVE-2026-YYYY7.5High

Suggested features

  • Show the CVE ID associated with a security update.
  • Show the CVSS score and severity (Critical/High/Medium/Low).
  • Show the highest CVSS score when an update fixes multiple CVEs.
  • Allow filtering security updates by CVSS severity.

This would make it much easier to identify and prioritize critical security updates across multiple hosts instead of treating all security updates equally.

It would be especially useful for large production environments where there may be hundreds of security updates.

Ideally, PatchMon could use distribution-specific security databases (Red Hat, Debian, Ubuntu, etc.) to correctly map package updates to their CVEs and CVSS scores.

0 Comments

Posting anonymously

No comments yet. Be the first to share your thoughts!