{"users":[{"id":4,"username":"adulau","name":"Alexandre Dulaunoy","avatar_template":"/user_avatar/discourse.ossbase.org/adulau/{size}/6_2.png","admin":true,"moderator":true,"trust_level":2},{"id":257,"username":"lva","name":"Lode Vanstechelman","avatar_template":"/user_avatar/discourse.ossbase.org/lva/{size}/682_2.png","trust_level":0},{"id":246,"username":"westonsteimel","name":"Weston Steimel","avatar_template":"/user_avatar/discourse.ossbase.org/westonsteimel/{size}/684_2.png","trust_level":1},{"id":5,"username":"cedric","name":"Cédric Bonhomme","avatar_template":"/user_avatar/discourse.ossbase.org/cedric/{size}/112_2.png","admin":true,"trust_level":2},{"id":260,"username":"nyanbinary","name":"Nyanbinary","avatar_template":"/user_avatar/discourse.ossbase.org/nyanbinary/{size}/689_2.png","trust_level":0},{"id":95,"username":"claudex","name":"Claudex","avatar_template":"/user_avatar/discourse.ossbase.org/claudex/{size}/227_2.png","trust_level":1},{"id":88,"username":"jayjacobs","name":"Jayjacobs","avatar_template":"/user_avatar/discourse.ossbase.org/jayjacobs/{size}/215_2.png","trust_level":1},{"id":99,"username":"rjb4standards","name":"Dick Brooks (BCG)","avatar_template":"/user_avatar/discourse.ossbase.org/rjb4standards/{size}/243_2.png","trust_level":1},{"id":161,"username":"jgamblin","name":"Jerry Gamblin","avatar_template":"/user_avatar/discourse.ossbase.org/jgamblin/{size}/574_2.png","trust_level":1},{"id":98,"username":"zmanion","name":"Art Manion","avatar_template":"/user_avatar/discourse.ossbase.org/zmanion/{size}/238_2.png","trust_level":0},{"id":84,"username":"todb","name":"Tod Beardsley","avatar_template":"/user_avatar/discourse.ossbase.org/todb/{size}/207_2.png","trust_level":0}],"primary_groups":[],"flair_groups":[],"topic_list":{"can_create_topic":false,"filter":"latest","more_topics_url":"/c/gcve/14?page=1","per_page":30,"top_tags":[{"id":15,"name":"gcve","slug":"gcve"},{"id":51,"name":"bcp-05","slug":"bcp-05"},{"id":2,"name":"vulnerability-lookup","slug":"vulnerability-lookup"},{"id":55,"name":"bcp-02","slug":"bcp-02"},{"id":60,"name":"bcp-12","slug":"bcp-12"},{"id":53,"name":"csaf","slug":"csaf"},{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"topics":[{"fancy_title":"About the GCVE category","id":112,"title":"About the GCVE category","slug":"about-the-gcve-category","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/f63b9b9e2a5455b29b84dafc4f53b53b6d660a4f_2_1024x288.png","created_at":"2025-07-03T06:25:01.724Z","last_posted_at":"2025-07-03T06:25:01.738Z","bumped":true,"bumped_at":"2025-08-29T09:55:58.680Z","archetype":"regular","unseen":false,"pinned":true,"unpinned":null,"excerpt":"The GCVE allocation system is a new, decentralized approach to vulnerability identification and numbering, designed to improve flexibility, scalability, and autonomy for participating entities. \nWhile remaining compatibl&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":32,"like_count":0,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE-BCP-11 - Community-Proposed Updates to Existing CVE Records","id":1110,"title":"GCVE-BCP-11 - Community-Proposed Updates to Existing CVE Records","slug":"gcve-bcp-11-community-proposed-updates-to-existing-cve-records","posts_count":15,"reply_count":7,"highest_post_number":15,"image_url":null,"created_at":"2026-07-13T16:26:13.434Z","last_posted_at":"2026-08-09T08:38:00.554Z","bumped":true,"bumped_at":"2026-08-09T08:38:00.554Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"GCVE-BCP-11 - Community-Proposed Updates to Existing CVE Records\n\nVersion: 1.0\nStatus: Draft (for Public Review)\nDate: 2026-07-13\nAuthors: GCVE Working Group\nBCP ID: BCP-11\n\nThis guide is distributed and available under &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":286,"like_count":12,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":2,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":257,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":246,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE BCP-05 and Markdown format","id":1120,"title":"GCVE BCP-05 and Markdown format","slug":"gcve-bcp-05-and-markdown-format","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-08-05T08:03:14.627Z","last_posted_at":"2026-08-05T08:03:14.783Z","bumped":true,"bumped_at":"2026-08-05T08:03:14.783Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Following the last discussion of the workshop about the markdown format in BCP-05, the following proposal was sent to the CVE Program: \n\n\nIf the answer is negative or it’s not implemented in 2026 by the CVE Program. An e&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":12,"like_count":0,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE-BCP-12 - Sighting Format","id":1085,"title":"GCVE-BCP-12 - Sighting Format","slug":"gcve-bcp-12-sighting-format","posts_count":9,"reply_count":4,"highest_post_number":9,"image_url":null,"created_at":"2026-04-28T12:51:07.875Z","last_posted_at":"2026-08-03T11:22:45.315Z","bumped":true,"bumped_at":"2026-08-03T11:22:45.315Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"A reminder based on the recent changes from @cedric to create a proper BCP for the description of the Sighting Format.","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":60,"name":"bcp-12","slug":"bcp-12"}],"tags_descriptions":{},"views":76,"like_count":4,"has_summary":false,"last_poster_username":"nyanbinary","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":null,"description":"Original Poster","user_id":4,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":5,"primary_group_id":null,"flair_group_id":null},{"extras":"latest","description":"Most Recent Poster","user_id":260,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE Lab - Proposal","id":1117,"title":"GCVE Lab - Proposal","slug":"gcve-lab-proposal","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-07-26T09:25:53.191Z","last_posted_at":"2026-07-26T09:25:53.420Z","bumped":true,"bumped_at":"2026-07-26T09:25:53.420Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"GCVE Lab\nDraft proposal \nThe GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System. \nThe lab allows the GCVE community to explore promising c&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":68,"like_count":2,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":2,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"BCP-05 and &ldquo;Adoption of CSAF for vulnerability reports submission pre-embargo using TLP markings and phased release to public CSAF report.&rdquo;","id":1116,"title":"BCP-05 and \"Adoption of CSAF for vulnerability reports submission pre-embargo using TLP markings and phased release to public CSAF report.\"","slug":"bcp-05-and-adoption-of-csaf-for-vulnerability-reports-submission-pre-embargo-using-tlp-markings-and-phased-release-to-public-csaf-report","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-07-16T14:41:40.843Z","last_posted_at":"2026-07-16T14:41:41.040Z","bumped":true,"bumped_at":"2026-07-16T14:41:41.040Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Reading this: \n\n\n“Adoption of CSAF for vulnerability reports submission pre-embargo using TLP markings and phased release to public CSAF report” \nBut I think it’s actually we do with BCP-05 (using a standard CVE-record f&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"},{"id":51,"name":"bcp-05","slug":"bcp-05"}],"tags_descriptions":{},"views":84,"like_count":0,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE corrections to upstream data?","id":1099,"title":"GCVE corrections to upstream data?","slug":"gcve-corrections-to-upstream-data","posts_count":12,"reply_count":9,"highest_post_number":12,"image_url":null,"created_at":"2026-06-09T10:08:54.338Z","last_posted_at":"2026-07-13T16:31:14.868Z","bumped":true,"bumped_at":"2026-07-13T16:31:14.868Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"I’m not sure if this is possible yet, or if it is intended for the future, but in the process of looking at some of the new Vendor/Product/CPE mapping stuff available at https://cpe.gcve.eu/ (which seems very well done!)&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":88,"like_count":11,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":2,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":null,"description":"Original Poster","user_id":246,"primary_group_id":null,"flair_group_id":null},{"extras":"latest","description":"Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"KEV (Known Exploited Vulnerabilities) - Potential Format (BCP-07)","id":744,"title":"KEV (Known Exploited Vulnerabilities) - Potential Format (BCP-07)","slug":"kev-known-exploited-vulnerabilities-potential-format-bcp-07","posts_count":45,"reply_count":28,"highest_post_number":46,"image_url":null,"created_at":"2025-12-24T09:33:03.445Z","last_posted_at":"2026-07-03T08:29:47.517Z","bumped":true,"bumped_at":"2026-07-03T08:29:47.517Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"KEV Assertion Format – Draft Specification (BCP-07)\nThis format describes a generic KEV (Known Exploited Vulnerability) assertion format. \nThe goal is to express who claims exploitation, when, based on what, where it was&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":952,"like_count":19,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":95,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":88,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":99,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":5,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Topic about extending CPE or PURL to support LLM models","id":1106,"title":"Topic about extending CPE or PURL to support LLM models","slug":"topic-about-extending-cpe-or-purl-to-support-llm-models","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/5220dab33021cc6c331c18bee5cb4a5db9437599_2_1024x512.png","created_at":"2026-06-23T14:02:28.627Z","last_posted_at":"2026-06-23T14:02:28.768Z","bumped":true,"bumped_at":"2026-06-23T14:02:28.768Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"After a discussion with Eireann Leverett in a chat room about fingerprinting, he asked how LLM software and tools should be classified by default. Is there an appropriate CPE vendor/product classification for them? \nThe &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":36,"like_count":0,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE BCP-05-X-01: AI-Assisted Vulnerability Information Annotation","id":1083,"title":"GCVE BCP-05-X-01: AI-Assisted Vulnerability Information Annotation","slug":"gcve-bcp-05-x-01-ai-assisted-vulnerability-information-annotation","posts_count":5,"reply_count":3,"highest_post_number":5,"image_url":null,"created_at":"2026-04-24T05:23:51.230Z","last_posted_at":"2026-06-23T08:17:56.315Z","bumped":true,"bumped_at":"2026-06-23T08:17:56.315Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"GCVE BCP-05-X-01: AI-Assisted Vulnerability Information Annotation\nStatus\nProposed Extension to GCVE BCP-05 \nAbstract\nThis document defines an extension to GCVE BCP-05 to support the annotation of vulnerability records w&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":51,"name":"bcp-05","slug":"bcp-05"}],"tags_descriptions":{},"views":96,"like_count":2,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":95,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Temporary Closure of Vulnerability Intake Windows - Potential Annex/Extension for GCVE BCP-02","id":1104,"title":"Temporary Closure of Vulnerability Intake Windows - Potential Annex/Extension for GCVE BCP-02","slug":"temporary-closure-of-vulnerability-intake-windows-potential-annex-extension-for-gcve-bcp-02","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-06-15T14:38:32.984Z","last_posted_at":"2026-06-15T14:38:33.170Z","bumped":true,"bumped_at":"2026-06-15T14:38:33.170Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Temporary Closure of Vulnerability Intake Windows\n(Potential annex or extension to  GCVE-BCP-02 - Practical Guide to Vulnerability Handling and Disclosure) \nOpen source maintainers MAY temporarily close or suspend vulner&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":55,"name":"bcp-02","slug":"bcp-02"}],"tags_descriptions":{},"views":116,"like_count":3,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":3,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Cpe-editor v1.0.0: Establishing the Foundation for Collaborative CPE &amp; PURL Mapping","id":1103,"title":"Cpe-editor v1.0.0: Establishing the Foundation for Collaborative CPE & PURL Mapping","slug":"cpe-editor-v1-0-0-establishing-the-foundation-for-collaborative-cpe-purl-mapping","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/e8ca1a93d32a13551c5e962132f5f03be6d36d75_2_1024x951.jpeg","created_at":"2026-06-14T15:04:38.936Z","last_posted_at":"2026-06-14T15:04:39.118Z","bumped":true,"bumped_at":"2026-06-14T15:04:39.118Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"cpe-editor v1.0.0 (2026-06-14)\nWe are thrilled to announce the official first release (v1.0.0) of cpe-editor, the platform powering cpe.gcve.eu. This initial release establishes a collaborative environment for managing C&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":42,"like_count":1,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE-BCP-08 - GCVE GNA Directory File (draft)","id":754,"title":"GCVE-BCP-08 - GCVE GNA Directory File (draft)","slug":"gcve-bcp-08-gcve-gna-directory-file-draft","posts_count":6,"reply_count":2,"highest_post_number":6,"image_url":null,"created_at":"2026-01-31T08:23:37.225Z","last_posted_at":"2026-05-29T13:02:46.636Z","bumped":true,"bumped_at":"2026-05-29T13:02:46.636Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Following various discussions and the meeting at FOSDEM, we will create the GCVE-BCP-08 describing the directory JSON format. \nGCVE-BCP-08 - GCVE GNA Directory File\nStatus of This Document\nThis document defines GCVE-BCP-&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":104,"like_count":4,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":5,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":161,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Vulnerability-Lookup 5.0 Released: Making Coordinated Vulnerability Disclosure Easier for GCVE GNAs","id":1096,"title":"Vulnerability-Lookup 5.0 Released: Making Coordinated Vulnerability Disclosure Easier for GCVE GNAs","slug":"vulnerability-lookup-5-0-released-making-coordinated-vulnerability-disclosure-easier-for-gcve-gnas","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/f476f322967210d2938913becfbee4389f022bea_2_1024x609.png","created_at":"2026-05-29T10:21:39.276Z","last_posted_at":"2026-05-29T10:21:39.444Z","bumped":true,"bumped_at":"2026-05-29T10:21:39.444Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"The GCVE initiative is pleased to welcome the release of Vulnerability-Lookup 5.0.0, a major new version of the open-source software that powers db.gcve.eu. \nThis release is especially important for the GCVE ecosystem: i&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":15,"like_count":1,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"CSAF and GCVE BCP-05/extensions","id":1093,"title":"CSAF and GCVE BCP-05/extensions","slug":"csaf-and-gcve-bcp-05-extensions","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/daea65dca3cc84409bf62463063021cf3b4dd941_2_1024x512.png","created_at":"2026-05-25T17:08:45.982Z","last_posted_at":"2026-05-25T17:08:46.139Z","bumped":true,"bumped_at":"2026-05-25T17:08:46.139Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"We had a quick discussion about the use of CSAF in GCVE and especially about BCP-05 (if we stick with CVE record format or going for something more versatile). \nIn order to review, what’s possible, we did a quick extensi&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"},{"id":53,"name":"csaf","slug":"csaf"}],"tags_descriptions":{},"views":25,"like_count":2,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":2,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Publishing GCVE enriched dumps with VLAI severity classification","id":1092,"title":"Publishing GCVE enriched dumps with VLAI severity classification","slug":"publishing-gcve-enriched-dumps-with-vlai-severity-classification","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-05-21T21:42:22.467Z","last_posted_at":"2026-05-21T21:42:22.666Z","bumped":true,"bumped_at":"2026-05-21T21:42:22.666Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"GCVE is not only about allocating vulnerability identifiers. It is also about building a practical, decentralized, and reproducible ecosystem around vulnerability publication, enrichment, and consumption. \nThe new gcve-e&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":23,"like_count":1,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE-BCP-09: Scope of a GCVE Record (early draft)","id":1041,"title":"GCVE-BCP-09: Scope of a GCVE Record (early draft)","slug":"gcve-bcp-09-scope-of-a-gcve-record-early-draft","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-03-28T10:09:54.800Z","last_posted_at":"2026-03-28T10:09:55.020Z","bumped":true,"bumped_at":"2026-03-28T10:09:55.020Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"GCVE-BCP-09: Scope of a GCVE Record\n\nDocument ID: GCVE-BCP-09\nTitle: Scope of a GCVE Record\nCategory: Best Current Practice\nStatus: Draft\n\nAbstract\nThis document clarifies what is actually recorded in GCVE. A GCVE record&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":28,"like_count":1,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Describing vulnerabilities in online services (SaaS, Cloud, web services)","id":731,"title":"Describing vulnerabilities in online services (SaaS, Cloud, web services)","slug":"describing-vulnerabilities-in-online-services-saas-cloud-web-services","posts_count":3,"reply_count":1,"highest_post_number":3,"image_url":null,"created_at":"2025-11-24T08:42:46.502Z","last_posted_at":"2026-03-27T07:54:50.732Z","bumped":true,"bumped_at":"2026-03-27T07:54:50.732Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Workshop Follow-up: Advisories for Online Services\nDuring our last workshop in Luxembourg on November 24th, a question was raised by a  GNA (GCVE Numbering Authorities) regarding the ability to record and publish securit&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":74,"like_count":1,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE BCP-03 Review and update required","id":1033,"title":"GCVE BCP-03 Review and update required","slug":"gcve-bcp-03-review-and-update-required","posts_count":4,"reply_count":2,"highest_post_number":4,"image_url":null,"created_at":"2026-03-17T05:44:41.104Z","last_posted_at":"2026-03-26T13:26:10.760Z","bumped":true,"bumped_at":"2026-03-26T13:26:10.760Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Following some design changes, we need to review if the urls are still applicable on the reference implementation. To be reviewed with @cedric","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":35,"like_count":3,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":5,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE.eu DB and official instance","id":726,"title":"GCVE.eu DB and official instance","slug":"gcve-eu-db-and-official-instance","posts_count":3,"reply_count":1,"highest_post_number":3,"image_url":null,"created_at":"2025-11-13T22:40:09.294Z","last_posted_at":"2026-03-07T17:27:36.603Z","bumped":true,"bumped_at":"2026-03-07T17:27:36.603Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"To support GCVE.eu, a dedicated database instance will be deployed specifically for the project. This new instance will complement the existing service at vulnerability.circl.lu and help distribute the overall load. Its &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":65,"like_count":3,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"CRA and GCVE overview","id":1017,"title":"CRA and GCVE overview","slug":"cra-and-gcve-overview","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/original/1X/b3b0a99f5d5a8e572f0e9924e56c8f2afdd77512.png","created_at":"2026-02-15T14:07:42.098Z","last_posted_at":"2026-02-15T14:07:42.224Z","bumped":true,"bumped_at":"2026-02-15T14:07:42.224Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Vendor as a GCVE GNA and decentralized vulnerability publication workflow\nWhat it means for a vendor to become a GNA in the GCVE model\nAcross GCVE BCPs, a GNA is treated as a publisher of vulnerability information and re&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":180,"like_count":1,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE BCP-06 drafting - Requirements and Evaluation Criteria for GCVE Numbering Authorities","id":732,"title":"GCVE BCP-06 drafting - Requirements and Evaluation Criteria for GCVE Numbering Authorities","slug":"gcve-bcp-06-drafting-requirements-and-evaluation-criteria-for-gcve-numbering-authorities","posts_count":6,"reply_count":3,"highest_post_number":6,"image_url":null,"created_at":"2025-11-27T05:34:08.758Z","last_posted_at":"2026-02-15T13:25:20.172Z","bumped":true,"bumped_at":"2026-02-15T13:25:20.172Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"This new document will define the requirements and evaluation criteria for GCVE Numbering Authorities (GNAs) operating within the GCVE ecosystem. It establishes a standardized framework to assess the extent to which GNAs&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":207,"like_count":3,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":95,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE will be at hackathon.lu - April 14th and 15th, 2026","id":757,"title":"GCVE will be at hackathon.lu - April 14th and 15th, 2026","slug":"gcve-will-be-at-hackathon-lu-april-14th-and-15th-2026","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-02-04T21:50:56.751Z","last_posted_at":"2026-02-04T21:50:56.894Z","bumped":true,"bumped_at":"2026-02-04T21:50:56.894Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"This 2-day, in-person hackathon, held in Luxembourg on April 14–15, 2026 (09:00–17:00), combines a hands-on open-source hackathon with an integrated public conference morning on April 14 (09:00–12:00). The event focuses &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":39,"name":"hackathon-2026","slug":"hackathon-2026"}],"tags_descriptions":{},"views":31,"like_count":1,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"CVE records tags and recommended taxonomies in GCVE","id":741,"title":"CVE records tags and recommended taxonomies in GCVE","slug":"cve-records-tags-and-recommended-taxonomies-in-gcve","posts_count":4,"reply_count":2,"highest_post_number":4,"image_url":null,"created_at":"2025-12-20T09:30:49.753Z","last_posted_at":"2026-01-31T06:54:46.105Z","bumped":true,"bumped_at":"2026-01-31T06:54:46.105Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Following the last working-group meeting with the MISP core team, many questions were raised concerning the tags and taxonomies used in the vulnerability ecosystem, including the CVE Program, GCVE, and others. \nThe CVE P&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":51,"like_count":0,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE-BCP-02 - Practical Guide to Vulnerability Handling and Disclosure","id":709,"title":"GCVE-BCP-02 - Practical Guide to Vulnerability Handling and Disclosure","slug":"gcve-bcp-02-practical-guide-to-vulnerability-handling-and-disclosure","posts_count":3,"reply_count":0,"highest_post_number":3,"image_url":null,"created_at":"2025-08-30T20:08:45.915Z","last_posted_at":"2026-01-25T11:09:43.030Z","bumped":true,"bumped_at":"2026-01-25T11:09:43.030Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Vulnerabilities in software can pose serious risks to users and organizations. A clear and effective process for handling and disclosing security vulnerabilities maintains user trust and protects systems. \nThis guide pro&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":79,"like_count":1,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Multiple CVSS entries per GCVE record","id":750,"title":"Multiple CVSS entries per GCVE record","slug":"multiple-cvss-entries-per-gcve-record","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-01-13T07:46:31.766Z","last_posted_at":"2026-01-13T07:46:31.919Z","bumped":true,"bumped_at":"2026-01-13T07:46:31.919Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"We have seen multiple cases where CVSS evaluation is difficult, or where different parties have differing points of view. We were therefore wondering how to represent multiple CVSS entries for the same CVE record (as it &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":23,"like_count":1,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":1,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE BCP-05 drafting - Best practices for the &ldquo;container&rdquo; format - modified CVE Record Format","id":121,"title":"GCVE BCP-05 drafting - Best practices for the \"container\" format - modified CVE Record Format","slug":"gcve-bcp-05-drafting-best-practices-for-the-container-format-modified-cve-record-format","posts_count":45,"reply_count":30,"highest_post_number":45,"image_url":null,"created_at":"2025-08-21T07:12:47.684Z","last_posted_at":"2026-01-02T13:17:17.419Z","bumped":true,"bumped_at":"2026-01-02T13:17:17.419Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"In BCP-03, we only describe the protocol and not the format. Nevertheless, we recommend using the CVE Record Format. During some tests with a new GNA, we discovered areas for improvement, and insightful feedback about th&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":812,"like_count":18,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":5,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":161,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":95,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":98,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Extending the GCVE Python cli with a vulnerability lookup command","id":722,"title":"Extending the GCVE Python cli with a vulnerability lookup command","slug":"extending-the-gcve-python-cli-with-a-vulnerability-lookup-command","posts_count":4,"reply_count":2,"highest_post_number":4,"image_url":null,"created_at":"2025-10-24T20:23:45.917Z","last_posted_at":"2025-10-27T00:17:24.117Z","bumped":true,"bumped_at":"2025-10-27T00:17:24.117Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"The idea is to extend the GCVE Python CLI with a vulnerability lookup command inspired by dig (Domain Information Groper). \nI initially considered implementing a new sub-command named vig, but I am not a fan of the name.&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":2,"name":"vulnerability-lookup","slug":"vulnerability-lookup"},{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":92,"like_count":3,"has_summary":false,"last_poster_username":"cedric","category_id":14,"op_like_count":2,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":5,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"GCVE BCP-04 drafting - Recommendations and best practices for ID allocation","id":119,"title":"GCVE BCP-04 drafting - Recommendations and best practices for ID allocation","slug":"gcve-bcp-04-drafting-recommendations-and-best-practices-for-id-allocation","posts_count":10,"reply_count":8,"highest_post_number":10,"image_url":null,"created_at":"2025-08-21T06:49:43.771Z","last_posted_at":"2025-09-16T20:17:35.455Z","bumped":true,"bumped_at":"2025-09-16T20:17:35.455Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Following various discussions about the after prefix part in GCVE, BCP-04 will include recommendations and best practices, especially for GNAs that do not have an ID generation and allocation process. \nAs mentioned in is&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":15,"name":"gcve","slug":"gcve"}],"tags_descriptions":{},"views":120,"like_count":5,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":5,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":95,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":84,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Beyond CVEs: Mastering the Landscape with Vulnerability-Lookup","id":706,"title":"Beyond CVEs: Mastering the Landscape with Vulnerability-Lookup","slug":"beyond-cves-mastering-the-landscape-with-vulnerability-lookup","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ossbase.org/uploads/default/optimized/1X/b13c6262043a0530a028ec8b57c2ded5c25b264d_2_1024x576.jpeg","created_at":"2025-08-29T07:31:18.463Z","last_posted_at":"2025-08-29T07:31:18.613Z","bumped":true,"bumped_at":"2025-08-29T07:31:18.613Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"The FIRSTCON 2025 video is now online including a quick description of the GCVE initiative. \nAlthough CVEs are a cornerstone of vulnerability management, they often present an incomplete view of the security landscape. V&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":2,"name":"vulnerability-lookup","slug":"vulnerability-lookup"}],"tags_descriptions":{},"views":38,"like_count":0,"has_summary":false,"last_poster_username":"adulau","category_id":14,"op_like_count":0,"pinned_globally":false,"featured_link":null,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":null,"flair_group_id":null}]}]}}