Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
GNOME is officially shortening its standard vulnerability disclosure window from 90 days to 30 days, a change that impacts upstream maintainers, downstream Linux distributions, and system administrators in how they handle software vulnerabilities. The policy shift, announced by long-time security coordinator Michael Catanzaro, addresses modern software patching realities and a growing influx of automated submissions.
Because GNOME is the default desktop environment on several major Linux distributions, changes to its security process can affect downstream maintainers and organizations that deploy GNOME-based workstations. The shorter disclosure window could reduce the time available for downstream distributions and organizations to prepare updates before vulnerability details become public.
The new policy introduces strict operational guidelines for how incoming security issues are handled across GNOME projects:
To understand the timeline shift, it helps to know why disclosure embargoes exist in the first place. 
Coordinated disclosure policies aim to give developers and downstream maintainers a protected window of time to investigate flaws, write patches, and coordinate repository updates before technical exploit details become public knowledge. Under the previous 90-day framework, however, that window no longer matched actual project behavior.
In practice, GNOME maintainers typically resolve valid security issues within one to three weeks, or they leave them unaddressed entirely. Keeping unpatched reports confidential for a full 90 days created administrative delays without providing practical benefits for patch development.
Moreover, the rise of automated tools had a dramatic impact on submission patterns. There are fewer reports that are written by humans, and more reports that are generated by AI. A large proportion of these automated submissions are of low quality, which significantly increases the triage burden on maintainers. Some open-source projects opted for immediate full disclosure for AI-generated reports, but GNOME opted for a more balanced 30-day window to ensure maintainers still have a reasonable window to fix legitimate issues.
When GNOME fixes a security issue, distribution maintainers package those changes, publish updates, and release security advisories. A shorter disclosure window gives each step in that process less time before vulnerability details may become public.
Downstream maintainers across Fedora Workstation, Ubuntu Desktop, and Debian face tighter turnaround times to build and test patches. If an issue remains unresolved when the 30-day clock runs out, technical details enter the public domain, leaving downstream maintainers with less time to validate and distribute updates before technical details become public.
System administrators and enterprise IT teams managing GNOME-heavy environments should adjust their operational expectations to align with the new timeline. Rather than tracking upstream GNOME announcements directly, security teams should monitor security notices issued by their specific Linux distribution. Organizations must be prepared for technical vulnerability details to become public sooner if upstream maintainers cannot reach a resolution within the 30-day window, meaning internal staging and QA windows for desktop updates may need to be streamlined.
Supporting this policy transition is an upcoming leadership change within the project. Catanzaro, who has managed GNOME security tracking largely alone since November 2020 with backing from Red Hat, announced plans to step down from coordinating security reports later this year.
Catanzaro will stop tracking newly reported issues on November 1, 2026, aiming to clear the remaining pipeline by December. The departure initiates a search for an experienced community successor to manage incoming reports, oversee disclosure deadlines, and coordinate CVE assignments under the new 30-day framework.