To combat volunteer burnout driven by a surge in AI-generated vulnerability reports, the OpenJS Foundation CNA will temporarily pause all security operations from September 17 to October 6, 2026. This planned break prioritizes team sustainability and encourages healthy boundaries for open-source maintainers across the ecosystem.

The OpenJS Foundation CNA (CVE Numbering Authority) will pause its security operations from September 17 to October 6, 2026 (both dates included). During this period our team will step back from day-to-day CNA work to rest, recharge, and return with renewed focus.
We are sharing this openly and ahead of time so reporters, maintainers, and the wider community know what to expect.
Over the last several months the volume of security advisories and CVE requests we coordinate has grown sharply. A significant part of that growth comes from reports generated or assisted by large language models. Many are low signal, many need careful human review to separate real issues from noise, and all of them take time and energy from a small group of volunteers. As the Foundation has noted, AI has lowered the barrier to generating security reports, but not the cost of handling them, and volunteer availability does not scale with report volume.
This sustained load has a real cost. Security work is demanding under normal conditions, and the current pace is not sustainable if we want the people behind it to stay healthy and effective. Taking a planned, well-communicated break is a deliberate step to protect the long-term health of the team and the quality of the work we do.
The break also coincides with the Node.js Collaborator Summit, where much of the community gathers in person. Pausing coordination work during that window lets our contributors take part fully and focus on the conversations that matter, rather than splitting their attention with incoming reports.
The OpenJS-hosted project Express is also joining this break. Read more from their team.
We are not the first to take this step, and that is exactly the point. The curl project recently ran what they called a "Summer of Bliss," a month-long pause on vulnerability intake, and described it afterwards as one of their best decisions in a long while. Their experience showed that a clearly announced break can give maintainers real rest without meaningful security consequences, and it encouraged other projects to consider the same.
We support the idea that maintainers need time off, including in the security space. Security is essential work, but the people who do it are volunteers, and their wellbeing is not optional. Normalizing breaks is part of building a security ecosystem that lasts.
From September 17 to October 6, 2026:
Emergency exception: if you are aware of a vulnerability that is being actively exploited, or a critical issue that poses immediate and serious risk, we will still respond. For genuine emergencies, reach out in the #security channel on the OpenJS Foundation Slack (join at https://slack-invite.openjsf.org/). This is a public channel, so please keep your first message high-level and free of sensitive details. The CNA team and other members can see it and will step in to help or move you to a direct message for the specifics. Clearly mark the message as urgent.
We also want to encourage maintainers across our projects, and across the wider ecosystem, to give themselves permission to take a break. Burnout is real for open source maintainers, and it is especially present in security work. Stepping away to rest is not a failure of responsibility, it is part of a healthier and more sustainable approach to the work. Long-term sustainability matters more than constant output.
If a planned pause helps you keep contributing over the years rather than burning out in a season, it is worth it. We hope our own break makes that a little easier to talk about.
Thank you to everyone who reports responsibly, and to the maintainers who carry this work. We will be back on October 7, 2026, rested and ready.
The OpenJS Foundation CNA team