# Vulnerability-Lookup 2.19.0

**URL:** <https://discourse.ossbase.org/t/vulnerability-lookup-2-19-0/735>\
**Category:** Vulnerability-Lookup\
**Tags:** vulnerability-lookup\
**Created:** [December 10, 2025, 6:41am UTC](https://discourse.ossbase.org/t/vulnerability-lookup-2-19-0/735 "2025-12-10T06:41:56Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![cedric](https://discourse.ossbase.org/user_avatar/discourse.ossbase.org/cedric/32/112_2.png) [@cedric](https://discourse.ossbase.org/u/cedric)\
**Post date:** [December 10, 2025, 6:41am UTC](https://discourse.ossbase.org/t/vulnerability-lookup-2-19-0/735/1 "2025-12-10T06:41:56Z")

</div>

We’re delighted to announce the release of **Vulnerability-Lookup 2.19.0**!

## What’s New

### GCVE: Global CVE Allocation System

We’re pleased to announce the publication of:

- [GCVE-BCP-02 – Practical Guide to Vulnerability Handling and Disclosure](https://gcve.eu/bcp/gcve-bcp-02/), and
- [GCVE-BCP-04 - Recommendations and Best Practices for ID Allocation](https://gcve.eu/bcp/gcve-bcp-04/)

This Best Current Practice document GCVE-BCP-02 provides actionable guidance for organisations,  
researchers, and GCVE Numbering Authorities (GNAs) on managing and disclosing  
vulnerabilities effectively, both **within the GCVE ecosystem and beyond**.

Vulnerability-Lookup **fully supports** these best practices for vulnerability disclosure,  
helping to promote responsible and effective handling of security issues.

### Graphical improvements

- Added Credits section for CVE v5 format (used by GCVE) and the OpenSSF Malicious Packages. [686e518](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/686e518), [3b39016](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3b39016), [7e9bf4f](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/7e9bf4f)
- Show CVE description on hover in /recent page (and for the card box of the index page). [#289](https://github.com/vulnerability-lookup/vulnerability-lookup/issues/289).
- Many templates have been improved, including the vulnerability detail page, the recent vulnerabilities list,  
severity score displays, and all HTML tables, allowing more information to be shown while keeping the interface clean and user-friendly.

**Tooltips for Bootstrap cardboxes**

 ![tooltip-cardbox](https://discourse.ossbase.org/uploads/default/original/1X/74dfcf597df19cff48912769cd94657b2c93a9fe.jpeg)

* * *

**Tooltips for lists of recent vulnerabilities**

 ![tooltip-recent-list](https://discourse.ossbase.org/uploads/default/original/1X/227392d8bd868e9fcb12b11236d0676259f0cd02.jpeg)

* * *

**New Credits section**

 ![credits](https://discourse.ossbase.org/uploads/default/original/1X/24c25bc11c43befdc7aa77a38662b4e56778cc4a.jpeg)

* * *

**Credits for the OpenSSF Malicious Packages**

 ![credits-ossf](https://discourse.ossbase.org/uploads/default/original/1X/c4db5ef8be8f4ac7ae8683028c17b78b7db86529.jpeg)

### Changes

- chg: [website] Reorganized and improved all Jinja filters especially the filters related to the parsing of CVE data. [f912ef4](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/f912ef4)
- chg: [templates] Improved the display of the severity related information for CVE and GitHub sources in the /recent page. [629dc7a](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/629dc7a)
- chg: [website] New layout for severity implemented for PySec advisories. [74387cd](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/74387cd)
- chg: [website] Added VLAI Severity score for PySec advisories. [3cfcc8d](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3cfcc8d)
- chg: [website] Extract and display credits from OSSF Malicious Packages sources. [3b39016](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3b39016)
- chg: [templates] Improved display of various tables. [88b73f1](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/88b73f1)
- chg: [website] Display more data in the vulnerability evolution charts. The growth is now displayed in a tooltip box. [b986dd3](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/b986dd3)

### Fixes

- fix: [backend] Remove notifications of users to be deleted. [3ad413f](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/3ad413f)
- chg: [templates] Fixed a display issue for Tailscale ids. [ef8a4a8](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ef8a4a8)
- fix: [templates] Handle single object case for the references section of record from the JVNDB. [f36689b](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/f36689b)

#### Security

- fix: [security] Unconfirm user accounts when their email address changes and send a password-reset token to the original email. [46f30a0](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/46f30a0)
- fix: [security] Remove all items from the session dict on logout [e2c54f7](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/e2c54f7)
- fix: [security] Regenerate session ID after a user updates their password. [2403fa6](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/2403fa6)
- fix: [security] Updating the password now requires the user to provide the current password. [a902f91](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a902f91)
- fix: [security] Sanitize related\_vulnerabilities field of bundles (in backend) and avoid injecting raw HTML when building the DOM (in frontend) when displaying. [1811ef9](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/1811ef9) - [GCVE-1-2025-0035](https://vulnerability.circl.lu/vuln/GCVE-1-2025-0035)
- fix: [security] All state changing endpoints are now using POST HTTP requests with a CSRF token. [a6c568d](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/a6c568d) - [GCVE-1-2025-0034](https://vulnerability.circl.lu/vuln/GCVE-1-2025-0034)
- fix: [security] The number of failed OTP attemprs is now recorded. The user account is blocked after 5 attempts. Admins have the possibility to monitor failed 2FA via the admin panel (list of users). [113b1fe](https://github.com/vulnerability-lookup/vulnerability-lookup/commit/113b1fe) - [GCVE-1-2025-0033](https://vulnerability.circl.lu/vuln/GCVE-1-2025-0033)

## Changelog

📂 For the full list of changes, check the GitHub release:

> **[Release Release 2.19.0 · vulnerability-lookup/vulnerability-lookup](https://github.com/vulnerability-lookup/vulnerability-lookup/releases/tag/v2.19.0)**
>
> What's New
> GCVE: Global CVE Allocation System
> We’re pleased to announce the publication of
> GCVE-BCP-02 – Practical Guide to Vulnerability Handling and Disclosure,
> now available in its version 1.3.
> ...

Thank you to all contributors and testers!

## Feedback and Support

If you find any issues or have suggestions, please open a ticket on our GitHub repository:

> **[vulnerability-lookup/vulnerability-lookup](https://github.com/vulnerability-lookup/vulnerability-lookup/issues/)**
>
> Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure ...

We appreciate your feedback!

## Follow Us on Fediverse/Mastodon

Stay updated on security advisories in real-time by following us on Mastodon:

> **[Vulnerability-Lookup (@vulnerability\_lookup@social.circl.lu)](https://social.circl.lu/@vulnerability_lookup/)**
>
> 23K Posts, 14 Following, 92 Followers · This account shares a variety of activities, including comments and bundles, related to events on the vulnerability.circl.lu community.
