Skip to content

Can CNAs publish vulnerability advisories lacking CVE IDs? #12

@zmanion

Description

@zmanion

Related to #9, we've observed "vendor" CNAs publishing advisories for vulnerabilities but lacking CVE IDs (nothing assigned by the CNA or another CNA, like a researcher or coordinator CNA).

The CVE Program tries not to dictate CNA (vendor or otherwise) vulnerabiltiy coordination, remediation, disclosure, and publication practices. CNAs are not required to fix vulnerabilities or publish advisories, and CNAs are to some extent not required to assign CVE IDs (although they may have a right of first refusal).

If a CNA publishes about a vulnerability, it seems reasonable to require that the CNA also assign and publish a CVE ID (or use a CVE ID assigned by another CNA). If the CNA does not, the burden falls on some other part of the CVE Program (likely a CNA-LR). A CNA close to (with appropriate scope for) a vulnerability, typically the vendor, is the least cost avoider, i.e., the least expensive way to produce a CVE ID assignment.

Should CNAs be required to assign (or use another assignment) for vulnerabilities the CNA publishes about? Should such a requirement be tied to the "vendor" CNA role?

Metadata

Metadata

Assignees

Labels

2026-Q1Rules changes under consideration for Q1 2026

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions