ICSE 2026
Sun 12 - Sat 18 April 2026 Rio de Janeiro, Brazil
Wed 15 Apr 2026 11:45 - 12:00 at Oceania V - Human and Social Aspects 1 Chair(s): Ben Hermann

The Common Vulnerabilities and Exposures (CVE) system plays a critical role in global cybersecurity by standardizing the identification and cataloging of software and hardware vulnerabilities. However, recent high-profile incidents highlight the potential pitfall of the system, indicating the space for improvement. Despite significant interests in and substantial studies on CVE system, there is a lack of understanding to what extent the participants are impacted, and what problems are exactly in the CVE ecosystem. To bridge the knowledge gap, we extensively collect blog posts, community discussions and editorial articles from various sources including Reddit, LWN.net and GitHub, and employ thematic analysis approach to identify the perceived adverse impact on participants as well as the inherent problems within the CVE ecosystem. Then we conducted a follow-up community survey with 77 participants for validation. The results unveil the impacts on various participants within the prevailing CVE ecosystem and for the first time comprehensively trace and elucidate the problems that may cause these impacts. Based on the findings and survey results, we propose a series of implications to mitigate existing problems within the CVE ecosystem, aiming to enhance its efficiency and health.

Wed 15 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

11:00 - 12:30
Human and Social Aspects 1Research Track / New Ideas and Emerging Results (NIER) at Oceania V
Chair(s): Ben Hermann University of Stuttgart
11:00
15m
Talk
Small Changes, Big Trouble: Demystifying and Parsing License Variants for Incompatibility Detection in the PyPI Ecosystem
Research Track
Weiwei Xu Peking University, Hengzhi Ye Peking University, Kai Gao University of Science and Technology Beijing, Minghui Zhou Peking University
Pre-print
11:15
15m
Talk
WhyFlow: Interrogative Debugger for Sensemaking Taint Analysis
Research Track
Burak Yetiştiren UCLA, Hong Jin Kang University of Sydney, Miryung Kim UCLA and Amazon Web Services
Link to publication DOI Pre-print
11:30
15m
Talk
Designing Abandabot: When Does Open Source Dependency Abandonment Matter?
Research Track
Courtney Miller Carnegie Mellon University, Hao He Carnegie Mellon University, Weigen Chen Carnegie Mellon University, Elizabeth Lin NC State University, Chenyang Yang , Bogdan Vasilescu Carnegie Mellon University, Christian Kästner Carnegie Mellon University
11:45
15m
Talk
Demystifying the CVE Ecosystem: Community-Perceived Impacts and Problems
Research Track
Yiliang Zhao Peking University, Hengzhi Ye Peking University, Minghui Zhou Peking University, Huaimin Wang
12:00
15m
Talk
Reading Between the Lines: Scalable User Feedback via Implicit Sentiment in Developer PromptsDistinguished Paper Award
New Ideas and Emerging Results (NIER)
Daye Nam University of California, Irvine, Malgorzata Salawa Google, Satish Chandra Meta Platforms, Inc.
12:15
15m
Talk
Revealing the Dark Matter: Connecting Tacit and System Knowledge in Human-AI Collaborations
New Ideas and Emerging Results (NIER)
Katherine R. Dearstyne University of Notre Dame, Christian Bird Microsoft Research, Carmen Badea Microsoft Research, Robert DeLine Microsoft Research