# Latest

**URL:** https://discourse.ossbase.org/latest.md

[Latest](https://discourse.ossbase.org/latest.md) · [Categories](https://discourse.ossbase.org/categories.md) · [Tags](https://discourse.ossbase.org/tags.md)

---

## [Welcome to ossbase.org! 👋](https://discourse.ossbase.org/t/welcome-to-ossbase-org/5)

<div class="topic-metadata">

**Author:** [@system](https://discourse.ossbase.org/u/system)\
**Replies:** 1\
**Last updated:** [October 31, 2025, 9:19am UTC](https://discourse.ossbase.org/t/welcome-to-ossbase-org/5 "2025-10-31T09:19:39Z")

</div>

We are so glad you joined us. ossbase.org Empowering Open Source Security Software Through Support, Autonomy, and Collaboration. Here are some things you can do to get started: :speaking\_head: Introduce yourself by …

---

## [GCVE Lab - patch2vuln is a command-line tool that turns a git-format patch into a structured draft vulnerability advisory using a locally hosted Ollama model](https://discourse.ossbase.org/t/gcve-lab-patch2vuln-is-a-command-line-tool-that-turns-a-git-format-patch-into-a-structured-draft-vulnerability-advisory-using-a-locally-hosted-ollama-model/1127)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 3\
**Last updated:** [September 18, 2026, 3:04pm UTC](https://discourse.ossbase.org/t/gcve-lab-patch2vuln-is-a-command-line-tool-that-turns-a-git-format-patch-into-a-structured-draft-vulnerability-advisory-using-a-locally-hosted-ollama-model/1127 "2026-09-18T15:04:34Z")

</div>

patch2vuln patch2vuln is a command-line tool that turns a git-format patch into a structured draft vulnerability advisory using a locally hosted Ollama model. It analyzes the patch, proposes a vulnerability title and de…

---

## [GCVE-BCP-11 - Community-Proposed Updates to Existing CVE Records](https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 16\
**Last updated:** [September 5, 2026, 8:34am UTC](https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110 "2026-09-05T08:34:23Z")

</div>

GCVE-BCP-11 - Community-Proposed Updates to Existing CVE Records Version: 1.0 Status: Draft (for Public Review) Date: 2026-07-13 Authors: GCVE Working Group BCP ID: BCP-11 This guide is distributed and available under …

---

## [GCVE Workshop - 22 September 2026 (14:00-18:00), Luxembourg Before The Vulnopticon Conference](https://discourse.ossbase.org/t/gcve-workshop-22-september-2026-1400-luxembourg-before-the-vulnopticon-conference/1126)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [September 2, 2026, 3:14pm UTC](https://discourse.ossbase.org/t/gcve-workshop-22-september-2026-1400-luxembourg-before-the-vulnopticon-conference/1126 "2026-09-02T15:14:09Z")

</div>

We are pleased to announce a GCVE workshop on 22 September 2026, from 14:00 to 18:00, hosted at the CIRCL/LHC offices in Luxembourg, just before the VulnOpticon conference. The workshop is free and open to everyone, but…

---

## [From a Research Paper to Running Code: Experimenting with Local Exploit Hazard in Vulnerability-Lookup](https://discourse.ossbase.org/t/from-a-research-paper-to-running-code-experimenting-with-local-exploit-hazard-in-vulnerability-lookup/1123)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [August 11, 2026, 3:25pm UTC](https://discourse.ossbase.org/t/from-a-research-paper-to-running-code-experimenting-with-local-exploit-hazard-in-vulnerability-lookup/1123 "2026-08-11T15:25:35Z")

</div>

One of the interesting characteristics of open-source security tooling is that it gives us a relatively direct path from research to experimentation. On 27 July 2026, Stephen Shaffer and Laura Voicu published the first …

---

## [GCVE BCP-05 and Markdown format](https://discourse.ossbase.org/t/gcve-bcp-05-and-markdown-format/1120)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [August 5, 2026, 8:03am UTC](https://discourse.ossbase.org/t/gcve-bcp-05-and-markdown-format/1120 "2026-08-05T08:03:14Z")

</div>

Following the last discussion of the workshop about the markdown format in BCP-05, the following proposal was sent to the CVE Program: If the answer is negative or it’s not implemented in 2026 by the CVE Program. An e…

---

## [Implementation of Modeling Local Exploit Hazard - A Bayesian Framework for Quantifying Exploit Risk and Operational Efficiency](https://discourse.ossbase.org/t/implementation-of-modeling-local-exploit-hazard-a-bayesian-framework-for-quantifying-exploit-risk-and-operational-efficiency/1119)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [August 5, 2026, 7:42am UTC](https://discourse.ossbase.org/t/implementation-of-modeling-local-exploit-hazard-a-bayesian-framework-for-quantifying-exploit-risk-and-operational-efficiency/1119 "2026-08-05T07:42:00Z")

</div>

Based on the following paper: A proposal implementation in

---

## [Playing with a Threat-Actor explorer (browser-local) from the MISP galaxy dataset](https://discourse.ossbase.org/t/playing-with-a-threat-actor-explorer-browser-local-from-the-misp-galaxy-dataset/1118)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 2\
**Last updated:** [August 4, 2026, 8:28pm UTC](https://discourse.ossbase.org/t/playing-with-a-threat-actor-explorer-browser-local-from-the-misp-galaxy-dataset/1118 "2026-08-04T20:28:40Z")

</div>

The misp-galaxy dataset contains a lot of details about threat-actor and I wanted to experiment with the new Pivotick library from my colleague. Navigating over the mess vendor and threat-actor name We recently intro…

---

## [GCVE-BCP-12 - Sighting Format](https://discourse.ossbase.org/t/gcve-bcp-12-sighting-format/1085)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 8\
**Last updated:** [August 3, 2026, 11:22am UTC](https://discourse.ossbase.org/t/gcve-bcp-12-sighting-format/1085 "2026-08-03T11:22:45Z")

</div>

A reminder based on the recent changes from @cedric to create a proper BCP for the description of the Sighting Format.

---

## [GCVE Lab - Proposal](https://discourse.ossbase.org/t/gcve-lab-proposal/1117)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [July 26, 2026, 9:25am UTC](https://discourse.ossbase.org/t/gcve-lab-proposal/1117 "2026-07-26T09:25:53Z")

</div>

GCVE Lab Draft proposal The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System. The lab allows the GCVE community to explore promising c…

---

## [BCP-05 and "Adoption of CSAF for vulnerability reports submission pre-embargo using TLP markings and phased release to public CSAF report."](https://discourse.ossbase.org/t/bcp-05-and-adoption-of-csaf-for-vulnerability-reports-submission-pre-embargo-using-tlp-markings-and-phased-release-to-public-csaf-report/1116)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [July 16, 2026, 2:41pm UTC](https://discourse.ossbase.org/t/bcp-05-and-adoption-of-csaf-for-vulnerability-reports-submission-pre-embargo-using-tlp-markings-and-phased-release-to-public-csaf-report/1116 "2026-07-16T14:41:41Z")

</div>

Reading this: “Adoption of CSAF for vulnerability reports submission pre-embargo using TLP markings and phased release to public CSAF report” But I think it’s actually we do with BCP-05 (using a standard CVE-record f…

---

## [GCVE corrections to upstream data?](https://discourse.ossbase.org/t/gcve-corrections-to-upstream-data/1099)

<div class="topic-metadata">

**Author:** [@westonsteimel](https://discourse.ossbase.org/u/westonsteimel)\
**Replies:** 11\
**Last updated:** [July 13, 2026, 4:31pm UTC](https://discourse.ossbase.org/t/gcve-corrections-to-upstream-data/1099 "2026-07-13T16:31:14Z")

</div>

I’m not sure if this is possible yet, or if it is intended for the future, but in the process of looking at some of the new Vendor/Product/CPE mapping stuff available at https://cpe.gcve.eu/ (which seems very well done!)…

---

## [What format should I add to Rulezet?](https://discourse.ossbase.org/t/what-format-should-i-add-to-rulezet/1109)

<div class="topic-metadata">

**Author:** [@ecrou-exact](https://discourse.ossbase.org/u/ecrou-exact)\
**Replies:** 0\
**Last updated:** [July 3, 2026, 10:01am UTC](https://discourse.ossbase.org/t/what-format-should-i-add-to-rulezet/1109 "2026-07-03T10:01:21Z")

</div>

As we continue to develop Rulezet, we are looking to expand the platform’s capabilities by supporting additional threat intelligence and detection rule formats. Our goal is to provide a comprehensive, centralized hub for…

---

## [KEV (Known Exploited Vulnerabilities) - Potential Format (BCP-07)](https://discourse.ossbase.org/t/kev-known-exploited-vulnerabilities-potential-format-bcp-07/744)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 44\
**Last updated:** [July 3, 2026, 8:29am UTC](https://discourse.ossbase.org/t/kev-known-exploited-vulnerabilities-potential-format-bcp-07/744 "2026-07-03T08:29:47Z")

</div>

KEV Assertion Format – Draft Specification (BCP-07) This format describes a generic KEV (Known Exploited Vulnerability) assertion format. The goal is to express who claims exploitation, when, based on what, where it was…

---

## [Topic about extending CPE or PURL to support LLM models](https://discourse.ossbase.org/t/topic-about-extending-cpe-or-purl-to-support-llm-models/1106)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [June 23, 2026, 2:02pm UTC](https://discourse.ossbase.org/t/topic-about-extending-cpe-or-purl-to-support-llm-models/1106 "2026-06-23T14:02:28Z")

</div>

After a discussion with Eireann Leverett in a chat room about fingerprinting, he asked how LLM software and tools should be classified by default. Is there an appropriate CPE vendor/product classification for them? The …

---

## [GCVE BCP-05-X-01: AI-Assisted Vulnerability Information Annotation](https://discourse.ossbase.org/t/gcve-bcp-05-x-01-ai-assisted-vulnerability-information-annotation/1083)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 4\
**Last updated:** [June 23, 2026, 8:17am UTC](https://discourse.ossbase.org/t/gcve-bcp-05-x-01-ai-assisted-vulnerability-information-annotation/1083 "2026-06-23T08:17:56Z")

</div>

GCVE BCP-05-X-01: AI-Assisted Vulnerability Information Annotation Status Proposed Extension to GCVE BCP-05 Abstract This document defines an extension to GCVE BCP-05 to support the annotation of vulnerability records w…

---

## [Temporary Closure of Vulnerability Intake Windows - Potential Annex/Extension for GCVE BCP-02](https://discourse.ossbase.org/t/temporary-closure-of-vulnerability-intake-windows-potential-annex-extension-for-gcve-bcp-02/1104)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [June 15, 2026, 2:38pm UTC](https://discourse.ossbase.org/t/temporary-closure-of-vulnerability-intake-windows-potential-annex-extension-for-gcve-bcp-02/1104 "2026-06-15T14:38:33Z")

</div>

Temporary Closure of Vulnerability Intake Windows (Potential annex or extension to GCVE-BCP-02 - Practical Guide to Vulnerability Handling and Disclosure) Open source maintainers MAY temporarily close or suspend vulner…

---

## [Cpe-editor v1.0.0: Establishing the Foundation for Collaborative CPE & PURL Mapping](https://discourse.ossbase.org/t/cpe-editor-v1-0-0-establishing-the-foundation-for-collaborative-cpe-purl-mapping/1103)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [June 14, 2026, 3:04pm UTC](https://discourse.ossbase.org/t/cpe-editor-v1-0-0-establishing-the-foundation-for-collaborative-cpe-purl-mapping/1103 "2026-06-14T15:04:39Z")

</div>

cpe-editor v1.0.0 (2026-06-14) We are thrilled to announce the official first release (v1.0.0) of cpe-editor, the platform powering cpe.gcve.eu. This initial release establishes a collaborative environment for managing C…

---

## [🔥 New in Vulnerability-Lookup: KEV Catalog Coverage!](https://discourse.ossbase.org/t/new-in-vulnerability-lookup-kev-catalog-coverage/1102)

<div class="topic-metadata">

**Author:** [@cedric](https://discourse.ossbase.org/u/cedric)\
**Replies:** 0\
**Last updated:** [June 12, 2026, 7:43am UTC](https://discourse.ossbase.org/t/new-in-vulnerability-lookup-kev-catalog-coverage/1102 "2026-06-12T07:43:50Z")

</div>

Vulnerability-Lookup now provides a coverage matrix on its KEV catalogs page, showing which Known Exploited Vulnerability catalogs (e.g. EUVD KEV, CISA KEV, CIRCL KEV) reference the most recently updated vulnerabilities.…

---

## [Vulnerability-Lookup 5.1.0](https://discourse.ossbase.org/t/vulnerability-lookup-5-1-0/1101)

<div class="topic-metadata">

**Author:** [@cedric](https://discourse.ossbase.org/u/cedric)\
**Replies:** 0\
**Last updated:** [June 11, 2026, 9:04am UTC](https://discourse.ossbase.org/t/vulnerability-lookup-5-1-0/1101 "2026-06-11T09:04:55Z")

</div>

We are pleased to announce the release of \*\*Vulnerability-Lookup 5.1.0\*\*! The highlight of this release is the new \*\*CNA Publication Service\*\*, which lets vulnerabilities from your local source be published to the offic…

---

## [GCVE-BCP-08 - GCVE GNA Directory File (draft)](https://discourse.ossbase.org/t/gcve-bcp-08-gcve-gna-directory-file-draft/754)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 5\
**Last updated:** [May 29, 2026, 1:02pm UTC](https://discourse.ossbase.org/t/gcve-bcp-08-gcve-gna-directory-file-draft/754 "2026-05-29T13:02:46Z")

</div>

Following various discussions and the meeting at FOSDEM, we will create the GCVE-BCP-08 describing the directory JSON format. GCVE-BCP-08 - GCVE GNA Directory File Status of This Document This document defines GCVE-BCP-…

---

## [Vulnerability-Lookup 5.0 Released: Making Coordinated Vulnerability Disclosure Easier for GCVE GNAs](https://discourse.ossbase.org/t/vulnerability-lookup-5-0-released-making-coordinated-vulnerability-disclosure-easier-for-gcve-gnas/1096)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [May 29, 2026, 10:21am UTC](https://discourse.ossbase.org/t/vulnerability-lookup-5-0-released-making-coordinated-vulnerability-disclosure-easier-for-gcve-gnas/1096 "2026-05-29T10:21:39Z")

</div>

The GCVE initiative is pleased to welcome the release of Vulnerability-Lookup 5.0.0, a major new version of the open-source software that powers db.gcve.eu. This release is especially important for the GCVE ecosystem: i…

---

## [Vulnerability-Lookup 5.0.0 released](https://discourse.ossbase.org/t/vulnerability-lookup-5-0-0-released/1095)

<div class="topic-metadata">

**Author:** [@cedric](https://discourse.ossbase.org/u/cedric)\
**Replies:** 0\
**Last updated:** [May 29, 2026, 9:32am UTC](https://discourse.ossbase.org/t/vulnerability-lookup-5-0-0-released/1095 "2026-05-29T09:32:02Z")

</div>

We are thrilled to announce the release of Vulnerability-Lookup 5.0.0! This major release centers on a new CNA-compliant API for managing the vulnerabilities of your local source, together with deep Vulnogram integratio…

---

## [CSAF and GCVE BCP-05/extensions](https://discourse.ossbase.org/t/csaf-and-gcve-bcp-05-extensions/1093)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [May 25, 2026, 5:08pm UTC](https://discourse.ossbase.org/t/csaf-and-gcve-bcp-05-extensions/1093 "2026-05-25T17:08:46Z")

</div>

We had a quick discussion about the use of CSAF in GCVE and especially about BCP-05 (if we stick with CVE record format or going for something more versatile). In order to review, what’s possible, we did a quick extensi…

---

## [Publishing GCVE enriched dumps with VLAI severity classification](https://discourse.ossbase.org/t/publishing-gcve-enriched-dumps-with-vlai-severity-classification/1092)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [May 21, 2026, 9:42pm UTC](https://discourse.ossbase.org/t/publishing-gcve-enriched-dumps-with-vlai-severity-classification/1092 "2026-05-21T21:42:22Z")

</div>

GCVE is not only about allocating vulnerability identifiers. It is also about building a practical, decentralized, and reproducible ecosystem around vulnerability publication, enrichment, and consumption. The new gcve-e…

---

## [Vulnerability-Lookup 4.6.0](https://discourse.ossbase.org/t/vulnerability-lookup-4-6-0/1091)

<div class="topic-metadata">

**Author:** [@cedric](https://discourse.ossbase.org/u/cedric)\
**Replies:** 0\
**Last updated:** [May 21, 2026, 11:37am UTC](https://discourse.ossbase.org/t/vulnerability-lookup-4-6-0/1091 "2026-05-21T11:37:37Z")

</div>

We are excited to announce the release of Vulnerability-Lookup 4.6.0! This version brings more transparency, new data sources, API improvements, notable UI enhancements, and several performance and stability fixes. Wha…

---

## [Vulnerability Report - April 2026](https://discourse.ossbase.org/t/vulnerability-report-april-2026/1090)

<div class="topic-metadata">

**Author:** [@cedric](https://discourse.ossbase.org/u/cedric)\
**Replies:** 0\
**Last updated:** [May 4, 2026, 9:44am UTC](https://discourse.ossbase.org/t/vulnerability-report-april-2026/1090 "2026-05-04T09:44:56Z")

</div>

Introduction This vulnerability report has been generated with the help of AI, using the VulnMCP tooling on top of Vulnerability-Lookup, with contributions from the platform’s community. It highlights the most frequentl…

---

## [AIL v6](https://discourse.ossbase.org/t/ail-v6/1087)

<div class="topic-metadata">

**Author:** [@ail\_project](https://discourse.ossbase.org/u/ail_project)\
**Replies:** 0\
**Last updated:** [April 29, 2026, 3:49pm UTC](https://discourse.ossbase.org/t/ail-v6/1087 "2026-04-29T15:49:08Z")

</div>

AIL v6.8 Released - Hunting, Graphs & Analyst Experience AIL v6.8 focuses on making hunting workflows smoother and the analyst interface easier to use. This release brings redesigned tracker and retro hunt pages, Markdow…

---

## [GCVE-BCP-10 : Improved Common Platform Enumeration for GCVE](https://discourse.ossbase.org/t/gcve-bcp-10-improved-common-platform-enumeration-for-gcve/1042)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 6\
**Last updated:** [April 26, 2026, 7:52pm UTC](https://discourse.ossbase.org/t/gcve-bcp-10-improved-common-platform-enumeration-for-gcve/1042 "2026-04-26T19:52:10Z")

</div>

GCVE-BCP-10: Improved Common Platform Enumeration for GCVE Document ID: GCVE-BCP-10 Title: Improved Common Platform Enumeration for GCVE Status: Draft Category: Best Current Practice Updates: CPE-compatible naming and m…

---

## [Vibe coding slide deck](https://discourse.ossbase.org/t/vibe-coding-slide-deck/1084)

<div class="topic-metadata">

**Author:** [@iglocska](https://discourse.ossbase.org/u/iglocska)\
**Replies:** 0\
**Last updated:** [April 24, 2026, 1:09pm UTC](https://discourse.ossbase.org/t/vibe-coding-slide-deck/1084 "2026-04-24T13:09:56Z")

</div>

For slides for the vibe coding presentation Vibe Coding - Scoping to Reduce Risks.pdf (427.5 KB)

[Next page](https://discourse.ossbase.org/latest.md?page=1)
