# \#gcve

**URL:** https://discourse.ossbase.org/tag/gcve/15.md

[Latest](https://discourse.ossbase.org/latest.md) · [Categories](https://discourse.ossbase.org/categories.md) · [Tags](https://discourse.ossbase.org/tags.md)

---

## [GCVE-BCP-11 - Community-Proposed Updates to Existing CVE Records](https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 16\
**Last updated:** [September 5, 2026, 8:34am UTC](https://discourse.ossbase.org/t/gcve-bcp-11-community-proposed-updates-to-existing-cve-records/1110 "2026-09-05T08:34:23Z")

</div>

GCVE-BCP-11 - Community-Proposed Updates to Existing CVE Records Version: 1.0 Status: Draft (for Public Review) Date: 2026-07-13 Authors: GCVE Working Group BCP ID: BCP-11 This guide is distributed and available under …

---

## [GCVE Workshop - 22 September 2026 (14:00-18:00), Luxembourg Before The Vulnopticon Conference](https://discourse.ossbase.org/t/gcve-workshop-22-september-2026-1400-luxembourg-before-the-vulnopticon-conference/1126)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [September 2, 2026, 3:14pm UTC](https://discourse.ossbase.org/t/gcve-workshop-22-september-2026-1400-luxembourg-before-the-vulnopticon-conference/1126 "2026-09-02T15:14:09Z")

</div>

We are pleased to announce a GCVE workshop on 22 September 2026, from 14:00 to 18:00, hosted at the CIRCL/LHC offices in Luxembourg, just before the VulnOpticon conference. The workshop is free and open to everyone, but…

---

## [GCVE Lab - Proposal](https://discourse.ossbase.org/t/gcve-lab-proposal/1117)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [July 26, 2026, 9:25am UTC](https://discourse.ossbase.org/t/gcve-lab-proposal/1117 "2026-07-26T09:25:53Z")

</div>

GCVE Lab Draft proposal The GCVE Lab is an open space for experimenting with new ideas, tools, formats, and services related to the Global CVE Allocation System. The lab allows the GCVE community to explore promising c…

---

## [BCP-05 and "Adoption of CSAF for vulnerability reports submission pre-embargo using TLP markings and phased release to public CSAF report."](https://discourse.ossbase.org/t/bcp-05-and-adoption-of-csaf-for-vulnerability-reports-submission-pre-embargo-using-tlp-markings-and-phased-release-to-public-csaf-report/1116)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [July 16, 2026, 2:41pm UTC](https://discourse.ossbase.org/t/bcp-05-and-adoption-of-csaf-for-vulnerability-reports-submission-pre-embargo-using-tlp-markings-and-phased-release-to-public-csaf-report/1116 "2026-07-16T14:41:41Z")

</div>

Reading this: “Adoption of CSAF for vulnerability reports submission pre-embargo using TLP markings and phased release to public CSAF report” But I think it’s actually we do with BCP-05 (using a standard CVE-record f…

---

## [KEV (Known Exploited Vulnerabilities) - Potential Format (BCP-07)](https://discourse.ossbase.org/t/kev-known-exploited-vulnerabilities-potential-format-bcp-07/744)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 44\
**Last updated:** [July 3, 2026, 8:29am UTC](https://discourse.ossbase.org/t/kev-known-exploited-vulnerabilities-potential-format-bcp-07/744 "2026-07-03T08:29:47Z")

</div>

KEV Assertion Format – Draft Specification (BCP-07) This format describes a generic KEV (Known Exploited Vulnerability) assertion format. The goal is to express who claims exploitation, when, based on what, where it was…

---

## [GCVE-BCP-08 - GCVE GNA Directory File (draft)](https://discourse.ossbase.org/t/gcve-bcp-08-gcve-gna-directory-file-draft/754)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 5\
**Last updated:** [May 29, 2026, 1:02pm UTC](https://discourse.ossbase.org/t/gcve-bcp-08-gcve-gna-directory-file-draft/754 "2026-05-29T13:02:46Z")

</div>

Following various discussions and the meeting at FOSDEM, we will create the GCVE-BCP-08 describing the directory JSON format. GCVE-BCP-08 - GCVE GNA Directory File Status of This Document This document defines GCVE-BCP-…

---

## [CSAF and GCVE BCP-05/extensions](https://discourse.ossbase.org/t/csaf-and-gcve-bcp-05-extensions/1093)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [May 25, 2026, 5:08pm UTC](https://discourse.ossbase.org/t/csaf-and-gcve-bcp-05-extensions/1093 "2026-05-25T17:08:46Z")

</div>

We had a quick discussion about the use of CSAF in GCVE and especially about BCP-05 (if we stick with CVE record format or going for something more versatile). In order to review, what’s possible, we did a quick extensi…

---

## [GCVE-BCP-09: Scope of a GCVE Record (early draft)](https://discourse.ossbase.org/t/gcve-bcp-09-scope-of-a-gcve-record-early-draft/1041)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [March 28, 2026, 10:09am UTC](https://discourse.ossbase.org/t/gcve-bcp-09-scope-of-a-gcve-record-early-draft/1041 "2026-03-28T10:09:55Z")

</div>

GCVE-BCP-09: Scope of a GCVE Record Document ID: GCVE-BCP-09 Title: Scope of a GCVE Record Category: Best Current Practice Status: Draft Abstract This document clarifies what is actually recorded in GCVE. A GCVE record…

---

## [Describing vulnerabilities in online services (SaaS, Cloud, web services)](https://discourse.ossbase.org/t/describing-vulnerabilities-in-online-services-saas-cloud-web-services/731)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 2\
**Last updated:** [March 27, 2026, 7:54am UTC](https://discourse.ossbase.org/t/describing-vulnerabilities-in-online-services-saas-cloud-web-services/731 "2026-03-27T07:54:50Z")

</div>

Workshop Follow-up: Advisories for Online Services During our last workshop in Luxembourg on November 24th, a question was raised by a GNA (GCVE Numbering Authorities) regarding the ability to record and publish securit…

---

## [GCVE.eu DB and official instance](https://discourse.ossbase.org/t/gcve-eu-db-and-official-instance/726)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 2\
**Last updated:** [March 7, 2026, 5:27pm UTC](https://discourse.ossbase.org/t/gcve-eu-db-and-official-instance/726 "2026-03-07T17:27:36Z")

</div>

To support GCVE.eu, a dedicated database instance will be deployed specifically for the project. This new instance will complement the existing service at vulnerability.circl.lu and help distribute the overall load. Its …

---

## [Vulnerability Report - January 2026](https://discourse.ossbase.org/t/vulnerability-report-january-2026/1021)

<div class="topic-metadata">

**Author:** [@cedric](https://discourse.ossbase.org/u/cedric)\
**Replies:** 0\
**Last updated:** [February 18, 2026, 9:12am UTC](https://discourse.ossbase.org/t/vulnerability-report-january-2026/1021 "2026-02-18T09:12:32Z")

</div>

Introduction This vulnerability report has been generated using data aggregated on Vulnerability-Lookup, with contributions from the platform’s community. It highlights the most frequently mentioned vulnerability for Ja…

---

## [Vulnerability-Lookup 3.0.0](https://discourse.ossbase.org/t/vulnerability-lookup-3-0-0/755)

<div class="topic-metadata">

**Author:** [@cedric](https://discourse.ossbase.org/u/cedric)\
**Replies:** 0\
**Last updated:** [February 2, 2026, 6:16pm UTC](https://discourse.ossbase.org/t/vulnerability-lookup-3-0-0/755 "2026-02-02T18:16:34Z")

</div>

We are glad to announce Vulnerability-Lookup 3.0.0. Our second release of 2026 is a major milestone, featuring GCVE-BCP-07 support. Now, every Vulnerability-Lookup instance can publish its own KEV catalog while integrat…

---

## [Criteria and Process for Feed Inclusion in Vulnerability-Lookup](https://discourse.ossbase.org/t/criteria-and-process-for-feed-inclusion-in-vulnerability-lookup/752)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 3\
**Last updated:** [January 23, 2026, 10:33am UTC](https://discourse.ossbase.org/t/criteria-and-process-for-feed-inclusion-in-vulnerability-lookup/752 "2026-01-23T10:33:14Z")

</div>

This document defines the criteria for adding new vulnerability feeds to Vulnerability-Lookup. Feed Inclusion Criteria A feed SHOULD be considered for inclusion if it meets one or more of the following criteria: If th…

---

## [Multiple CVSS entries per GCVE record](https://discourse.ossbase.org/t/multiple-cvss-entries-per-gcve-record/750)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 0\
**Last updated:** [January 13, 2026, 7:46am UTC](https://discourse.ossbase.org/t/multiple-cvss-entries-per-gcve-record/750 "2026-01-13T07:46:31Z")

</div>

We have seen multiple cases where CVSS evaluation is difficult, or where different parties have differing points of view. We were therefore wondering how to represent multiple CVSS entries for the same CVE record (as it …

---

## [GCVE BCP-05 drafting - Best practices for the "container" format - modified CVE Record Format](https://discourse.ossbase.org/t/gcve-bcp-05-drafting-best-practices-for-the-container-format-modified-cve-record-format/121)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 44\
**Last updated:** [January 2, 2026, 1:17pm UTC](https://discourse.ossbase.org/t/gcve-bcp-05-drafting-best-practices-for-the-container-format-modified-cve-record-format/121 "2026-01-02T13:17:17Z")

</div>

In BCP-03, we only describe the protocol and not the format. Nevertheless, we recommend using the CVE Record Format. During some tests with a new GNA, we discovered areas for improvement, and insightful feedback about th…

---

## [Extending the GCVE Python cli with a vulnerability lookup command](https://discourse.ossbase.org/t/extending-the-gcve-python-cli-with-a-vulnerability-lookup-command/722)

<div class="topic-metadata">

**Author:** [@cedric](https://discourse.ossbase.org/u/cedric)\
**Replies:** 3\
**Last updated:** [October 27, 2025, 12:17am UTC](https://discourse.ossbase.org/t/extending-the-gcve-python-cli-with-a-vulnerability-lookup-command/722 "2025-10-27T00:17:24Z")

</div>

The idea is to extend the GCVE Python CLI with a vulnerability lookup command inspired by dig (Domain Information Groper). I initially considered implementing a new sub-command named vig, but I am not a fan of the name.…

---

## [GCVE BCP-04 drafting - Recommendations and best practices for ID allocation](https://discourse.ossbase.org/t/gcve-bcp-04-drafting-recommendations-and-best-practices-for-id-allocation/119)

<div class="topic-metadata">

**Author:** [@adulau](https://discourse.ossbase.org/u/adulau)\
**Replies:** 9\
**Last updated:** [September 16, 2025, 8:17pm UTC](https://discourse.ossbase.org/t/gcve-bcp-04-drafting-recommendations-and-best-practices-for-id-allocation/119 "2025-09-16T20:17:35Z")

</div>

Following various discussions about the after prefix part in GCVE, BCP-04 will include recommendations and best practices, especially for GNAs that do not have an ID generation and allocation process. As mentioned in is…

---

## [GCVE BCP-03 - Decentralized Publication Standard implemented in Vulnerability-Lookup](https://discourse.ossbase.org/t/gcve-bcp-03-decentralized-publication-standard-implemented-in-vulnerability-lookup/106)

<div class="topic-metadata">

**Author:** [@cedric](https://discourse.ossbase.org/u/cedric)\
**Replies:** 0\
**Last updated:** [June 13, 2025, 8:50am UTC](https://discourse.ossbase.org/t/gcve-bcp-03-decentralized-publication-standard-implemented-in-vulnerability-lookup/106 "2025-06-13T08:50:35Z")

</div>

We’re excited to announce the release of Vulnerability-Lookup 2.11.0 — and it comes with a major milestone for decentralized vulnerability publication! What’s New GCVE-BCP-03 - Decentralized Publication Standard The GCV…
