GCVE-BCP-07 - Known Exploited Vulnerability - KEV Assertion Format updated to version 2.1
Following the PTS 2026 workshop in Lille, a new version of GCVE-BCP-07 has been published.
This version introduces the index reference file format, available at https://gcve.eu/dist/references.json, and adds new metadata fields, including licenses, as requested by ENISA.
BCP-07
BCP-07 describes individual KEV assertions, but implementers also need a way to discover which organisations publish KEV catalogues and where their machine-readable feeds are located. The GCVE initiative publishes a non-mandatory KEV source index at https://gcve.eu/dist/references.json and maintains the source file at gcve.eu/static/dist/references.json at main · gcve-eu/gcve.eu · GitHub.
The index is a catalogue of KEV catalogues. It is not authoritative for the content of any listed catalogue and it is not required for a producer to publish BCP-07 KEV assertions. Its purpose is to facilitate discovery, correlation, and stable attribution of KEV catalogues, especially where gcve.origin_uuid or evidence[].gcve.origin_uuid values need to be resolved to a known source.