Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GCVE is an open, decentralized system for identifying, publishing, and exchanging software vulnerability information. It adds a way for independent authorities to issue and share vulnerability records while keeping existing CVE identifiers in scope: GCVE describes itself as complementary to CVE, not a replacement. The initiative was announced in 2025; its public database, db.gcve.eu, launched on January 7, 2026.

What is GCVE?

The Global CVE (GCVE) initiative is an open approach to vulnerability identification, publication, and exchange. It is operated by CIRCL, the Computer Incident Response Center Luxembourg. The project’s goal is to let independent organizations publish vulnerability information under their own authority while making those records discoverable and usable across systems. GCVE’s About page describes the initiative as an open, decentralised approach to vulnerability identification, publication, and exchange.

GCVE includes both an identifier scheme and services for discovering and working with vulnerability records. Its design is decentralized: participating authorities manage identifiers and records within their own declared scope and policies, rather than relying on a single central organization to assign every identifier.

How does the decentralized model work?

Independent authorities issue identifiers

A GCVE Numbering Authority (GNA) is an authorized participant that can allocate GCVE identifiers and publish associated records. GNAs may include vendors, open-source projects, CSIRTs or CERTs, vulnerability databases, and research organizations. Each authority defines its scope, governance, disclosure model, and data practices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A commonly used identifier form is GCVE-<GNA-ID>-<YEAR>-<UNIQUE-ID>; the broader documented form is GCVE-<GNA-ID>-<GNA-VALUE>. The GNA ID identifies the authority that assigned the identifier, providing provenance. GNAs do not need to request identifier blocks from one central allocation authority. That autonomy is intended to support a broad range of publishers, while shared practices help their systems exchange information.

A directory helps consumers find participants

GCVE provides a shared directory through which consumers can discover participating GNAs and their published information. The directory and common machine-readable practices are important to the model: decentralization does not mean each publisher must invent an entirely incompatible way to describe or expose records.

However, a shared directory is not the same as centralized editorial review. A GNA publishes according to its own stated scope and policies; GCVE does not claim that every record from every authority is centrally adjudicated. Consumers should assess which authorities they trust and what each authority covers.

Does GCVE replace CVE?

No. GCVE explicitly describes itself as complementary to the existing CVE system. It reserves GNA ID 0 to represent CVE identifiers within the GCVE namespace. For example, CVE-2023-40224 can also be represented as GCVE-0-2023-40224. The mapping preserves the original CVE identifier rather than suggesting that it has been superseded. The GCVE FAQ notes that software may need explicit support to parse and display identifiers beginning with GCVE-0-.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That detail matters for organizations maintaining vulnerability inventories, feeds, integrations, and user interfaces. Before consuming or displaying GCVE data, check whether the relevant systems recognize the identifier form and whether they can map GNA 0 identifiers to their existing CVE handling.

What launched, and when?

The GCVE initiative was announced in 2025 as a decentralized approach to vulnerability identification and numbering. A later milestone was the public launch of db.gcve.eu on January 7, 2026. The database is described as an open, freely accessible vulnerability advisory database; the launch announcement said it aggregated and correlated information from more than 25 public sources. That figure is what the initiative reported at launch, not an independently audited or necessarily current source count. See the dated announcement in the GCVE announcement archive.

What software powers GCVE services?

CIRCL maintains Vulnerability-Lookup, the open-source platform powering GCVE services. It is described as identifier-agnostic and designed to correlate vulnerability information from multiple sources. It also supports publication and synchronization workflows.

For coordinated vulnerability disclosure, Vulnerability-Lookup integrates Vulnogram for drafting and publishing advisories compatible with CVE 5.2 and GCVE-BCP-05. It can also synchronize information with other instances. These capabilities connect the decentralized model to practical workflows for advisory authors and data consumers. More details are available in the platform’s About page.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What practices help independent systems interoperate?

GCVE publishes Best Current Practices (BCPs) covering areas such as directory signing and verification, vulnerability handling and disclosure, decentralized publication, identifier allocation, record formats, GNA requirements, known-exploited-vulnerability assertions, record scope, product enumeration, and provenance.

The project describes BCP adherence as non-mandatory but strongly recommended for safety, usability, and compatibility. Status matters: a published practice is not the same as a document under public review or a draft. The catalogue accessed October 4, 2026 listed these statuses and versions:

BCP Status and version listed
BCP-02 Version 1.8, published September 2026
BCP-03 Version 1.6, published September 2026
BCP-07 Version 2.3, published September 2026
BCP-05 Version 1.7, published for public review
BCP-06, BCP-09, BCP-10, and BCP-12 Drafts for public review; versions not stated in the catalogue

These statuses can change. Check the GCVE BCP catalogue for the current status and version before building an implementation around a particular practice.

What should an organization consider before using GCVE?

  • Authority and trust: Identify the GNAs relevant to your products or threat model, and review each authority’s stated scope and disclosure policy.
  • Identifier compatibility: Confirm that downstream tools can parse and display GCVE identifiers, including the GNA 0 form used for CVE mappings.
  • Record compatibility: Check which record formats and practices your tools support, and distinguish published BCPs from review drafts.
  • Operational needs: Decide whether you only need to consume records or also intend to allocate identifiers, draft and publish advisories, or synchronize data through software such as Vulnerability-Lookup.

GCVE’s stated benefits, including scalability and resilience, are design aims of its decentralized model; the cited project material does not establish them as independently measured outcomes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.