94 to 100% of Security Issue Arrivals Land in Queues Already At or Over Capacity, Making Remediation a Flow Problem Not a Ranking One
arXiv 2608.28509 (2026-08-28, cs.SE) argues that as AI accelerates vulnerability discovery, remediation throughput becomes a tighter constraint than prioritisation accuracy, and tests it against Apache Jira, Mozilla Bugzilla, Red Hat security errata, five public Jira organisations and an npm dependency graph. Apache resolution times are strongly heavy-tailed and 94 to 100% of arrivals in the primary trackers enter queues estimated at or above capacity, while queue-context predictive models offer only moderate discrimination and are largely matched by simple project-level baselines. Flow-control effects are larger: overloaded-to-draining transitions shorten resolution times, severity-first sequencing reduces critical-item delay at fixed capacity, and spare capacity helps only where demand actually is or can be routed through expertise connections.
↳ Follow the thread