The taxonomy of buried fixes.
A living catalog of security patches that vendors merged without disclosure. Public entries are sourced from MITRE filings and coordinated disclosure. Embargoed entries are visible to regulators and law enforcement only.
A living catalog of security patches that vendors merged without disclosure. A silent patch is a fix that ships without an advisory, without an identifier, without a word to the people running the code. The vulnerability was real. The remediation is in the repository. Everything between those two facts was left out. The consequences run downstream. Forks that never pull the commit stay exploitable indefinitely. Operators budget against a threat picture that omits the patch entirely. And the historical record shows a product that was never vulnerable in the first place. This catalog exists to close that gap. Each entry pairs the underlying flaw with the commit that quietly resolved it and the disclosure that never followed. Public entries are sourced from MITRE filings and coordinated disclosure. Embargoed entries are visible to regulators and law enforcement only.What’s in the record.
Each entry below is a real silent patch detected by our pipeline. Public entries link to MITRE filings or coordinated disclosure. Embargoed entries appear with key identifying details redacted — full records are accessible to verified regulators.
Regulators see everything.
The public sees what’s safe to release.
Embargoed entries protect ongoing investigations and downstream users still exposed to the vulnerability. Regulators with jurisdiction get the unredacted record.
Securities regulators, financial supervisory authorities, privacy commissioners, and law enforcement agencies receive unrestricted access to the full silent patch dataset at no cost. The data exists to make markets transparent. Charging the entities responsible for transparency would defeat the purpose.
If your office has the authority to act on what’s documented here, request credentialed access. The complete record — including the redacted vendor names, exploit timelines, and downstream exposure maps — is yours.
Request Regulator Access →Credentialed Access Includes
- Unredacted vendor names for every embargoed entry in the database
- Exploit timelines mapping patch dates against incident events
- Downstream exposure maps identifying affected operators, forks, and dependent systems
- Chain-of-custody documentation for evidentiary use in enforcement proceedings
- Expert consultation on technical findings and supplementary filings
- Real-time alerts when newly detected silent patches match your jurisdiction
The methodology.
Every entry in the database passes through three phases of verification before it appears in the public record.
Continuous monitoring.
Proprietary tooling monitors commit histories across nine production ecosystems. Patches matching security-fix patterns are flagged for analysis regardless of whether the vendor labeled them as such.
Falsification-first review.
Each candidate is tested against the pre-fix codebase to confirm the vulnerability exists, the patch resolves it, and no public disclosure was issued at the time of merge. False positives are dropped.
Coordinated or filed.
Verified findings are routed through coordinated disclosure where the vendor cooperates, or filed directly with MITRE and the relevant regulator where they do not. The database reflects current status.
The full record is behind the redactions.
If you have regulatory authority or active investigative need, request credentialed access. If you’re a vendor whose code is in this database, your remediation timeline matters.
