The public GCVE registry now lists CVD Portal as GCVE Numbering Authority 126. This registration is live. The public allocation service, the retrieval API, and the data dump are planned work and are not yet live.
What a GNA is and what GCVE means
GCVE is a distributed vulnerability identifier system. A GCVE Numbering Authority receives a numeric GNA ID and allocates identifiers within that namespace. The GNA does not allocate for other namespaces.
GCVE does not replace CVE. CVE assigns identifiers through a different process. GCVE assigns through another. Both systems can reference the same vulnerability.
The planned identifier format
The planned identifier structure is
GCVE-126-<manufacturer-slug>-<sequence>. For example,
GCVE-126-acme-0001. The format is stable. The manufacturer slug is fixed at the tenant
level. The sequence is sequential within that namespace.
CVD Portal is the assigning GNA. The tenant is the affected manufacturer and the advisory owner. The tenant validates the vulnerability. A transaction allocates the next identifier in the sequence. An immutable record stores the allocation.
Embargo, publication, and record integrity
Embargo controls protect unpublished data. Publication connects the GCVE record, the public advisory, the CSAF 2.0 document, and any related identifiers.
Identifiers are not reused. Corrections create a new record version. Withdrawals change the status without changing the identifier.
Minimum planned record
The planned minimum record contains the following fields.
- GCVE ID
- GNA ID
- Tenant and stable manufacturer slug
- Affected manufacturer and product
- Advisory title and URL
- Allocation date
- Publication date
- Update date
- Status
- Related IDs
- Version
- Audit history
Governance and best practice
The GNA registration follows GCVE-BCP-04. The allocation policy follows GCVE-BCP-05.
The registry entry is live at gcve.eu/gna/126. The public allocation service, retrieval API, and data dump are planned.
CVD Portal is the platform. See cvdportal.com for the disclosure portal, the CRA compliance workspace, and the Article 14 reporting workflow.