{"id":86286,"date":"2025-04-09T13:02:44","date_gmt":"2025-04-09T20:02:44","guid":{"rendered":"https:\/\/github.blog\/?p=86286"},"modified":"2025-04-09T13:02:44","modified_gmt":"2025-04-09T20:02:44","slug":"how-to-request-a-change-to-a-cve-record","status":"publish","type":"post","link":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/","title":{"rendered":"How to request a change to a CVE record"},"content":{"rendered":"<!DOCTYPE html PUBLIC \"-\/\/W3C\/\/DTD HTML 4.0 Transitional\/\/EN\" \"http:\/\/www.w3.org\/TR\/REC-html40\/loose.dtd\">\n<html><body><p>Ever come across a <a href=\"https:\/\/github.blog\/security\/supply-chain-security\/securing-the-open-source-supply-chain-the-essential-role-of-cves\/\">Common Vulnerabilities and Exposures (CVE) ID<\/a> affecting software you use or maintain and thought the information could be better?<\/p>\n<p>CVE IDs are a widely-used system for tracking software vulnerabilities. When a vulnerable dependency affects your software, you can <a href=\"https:\/\/docs.github.com\/en\/code-security\/security-advisories\/working-with-repository-security-advisories\/creating-a-repository-security-advisory\">create a repository security advisory<\/a> to alert others. But if you want your insight to reach the most upstream data source possible, you&rsquo;ll need to contact the CVE Numbering Authority (CNA) that issued the vulnerability&rsquo;s CVE ID.<\/p>\n<p>GitHub, as part of a community of <a href=\"https:\/\/www.cve.org\/ProgramOrganization\/CNAs\">over 400 CNAs<\/a>, can help in cases when GitHub issued the CVE (such as with <a href=\"https:\/\/github.com\/github\/advisory-database\/pull\/2523\">this community contribution<\/a>). And with just a few key details, you can identify  the right CNA and reach out with the necessary context. This guide shows you how.<\/p>\n<h2 id=\"step-1-find-the-cna-that-issued-the-cve\" id=\"step-1-find-the-cna-that-issued-the-cve\" ><a class=\"heading-link\" href=\"#step-1-find-the-cna-that-issued-the-cve\">Step 1: Find the CNA that issued the CVE<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>Every CVE record contains an entry that includes the name of the CNA that issued the CVE ID. The CNA is responsible for updating the CVE record after its initial publication, so any requests should be directed to them.<\/p>\n<p>On <a href=\"http:\/\/cve.org\">cve.org<\/a>, the CNA is listed as the first piece of information under the &ldquo;Required CVE Record Information&rdquo; header. The information is also available on the right side of the page.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2025\/04\/Screenshot-2025-03-13-at-6.30.12%E2%80%AFPM-2.png?resize=1024%2C590\" alt=\"A screenshot of the cve.org record for CVE-2023-29012, with a yellow rectangle drawn around the &ldquo;CNA&rdquo; field to draw attention to the fact that &ldquo;GitHub (Maintainer Security Advisories)&rdquo; is the CNA for CVE-2023-29012.\" width=\"1024\" height=\"590\" class=\"alignnone size-full wp-image-86309 width-fit\"><\/p>\n<p>On <a href=\"http:\/\/nvd.nist.gov\">nvd.nist.gov<\/a>, information about the issuing CNA is available in the &ldquo;QUICK INFO&rdquo; box. The issuing CNA is called &ldquo;Source&rdquo;.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2025\/04\/Screenshot-2025-03-13-at-6.30.39%E2%80%AFPM.png?resize=1024%2C590\" alt=\"A screenshot of the nist.nvd.gov record for CVE-2023-29012, with a yellow rectangle drawn around the &ldquo;Source&rdquo; field to draw attention to the fact that &ldquo;GitHub, Inc.&rdquo; is the CNA for CVE-2023-29012.\" width=\"1024\" height=\"590\" class=\"alignnone size-full wp-image-86289 width-fit\"><\/p>\n<h2 id=\"step-2-find-the-contact-information-for-the-cna\" id=\"step-2-find-the-contact-information-for-the-cna\" ><a class=\"heading-link\" href=\"#step-2-find-the-contact-information-for-the-cna\">Step 2: Find the contact information for the CNA<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>After identifying the CNA from the CVE record, locate their official contact information to request updates or changes. That information is available on the CNA partners website at <a href=\"https:\/\/www.cve.org\/PartnerInformation\/ListofPartners\">https:\/\/www.cve.org\/PartnerInformation\/ListofPartners<\/a>.<\/p>\n<p>Search for the CNA&rsquo;s name in the search bar. Some organizations may have more than one CNA, so make sure that the CVE you want corresponds to the correct CNA.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2025\/04\/Screenshot-2025-03-13-at-6.31.00%E2%80%AFPM.png?resize=1024%2C590\" alt=\"A screenshot of the cve.org &ldquo;List of Partners.&rdquo; The &ldquo;Search&rdquo; bar shows &ldquo;GitHub,&rdquo; being searched for, with two results of the search shown under the search bar. Those results are &ldquo;GitHub, Inc.,&rdquo; the CNA that matches the CNA responsible for CVE-2023-29012, and &ldquo;GitHub, Inc. (Products Only),&rdquo; a different CNA that GitHub also operates.\" width=\"1024\" height=\"590\" class=\"alignnone size-full wp-image-86287 width-fit\"><\/p>\n<p>The left column, under &ldquo;Partner,&rdquo; has the name of the CNA that links to a profile page with its scope and contact information.<\/p>\n<h2 id=\"step-3-contact-the-cna\" id=\"step-3-contact-the-cna\" ><a class=\"heading-link\" href=\"#step-3-contact-the-cna\">Step 3: Contact the CNA<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>Most CNAs have an email address for CVE-related communications. Click the link under &ldquo;Step 2: Contact&rdquo; that says <strong>Email<\/strong> to find the CNA&rsquo;s email address.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2025\/04\/Screenshot-2025-03-13-at-6.32.01%E2%80%AFPM.png?resize=1024%2C590\" alt=\"A screenshot of the cve.org entry for the CNA &ldquo;GitHub, Inc.&rdquo; A yellow rectangle is drawn around a header and a link. The header reads &ldquo;Step 2: Contact&rdquo; and shows a link that says &ldquo;Email&rdquo; directly below the header.\" width=\"1024\" height=\"590\" class=\"alignnone size-full wp-image-86290 width-fit\"><\/p>\n<p>The most notable exception to the general preference for email communication among CNAs is the <a href=\"https:\/\/www.cve.org\/PartnerInformation\/ListofPartners\/partner\/mitre\">MITRE Corporation<\/a>, the world&rsquo;s most prolific CVE Numbering Authority. MITRE uses a webform at <a href=\"https:\/\/cveform.mitre.org\/\">https:\/\/cveform.mitre.org\/<\/a> for submitting requests to create, update, dispute, or reject CVEs.<\/p>\n<h2 id=\"what-to-include-in-your-communication-to-the-cna\" id=\"what-to-include-in-your-communication-to-the-cna\" ><a class=\"heading-link\" href=\"#what-to-include-in-your-communication-to-the-cna\">What to include in your communication to the CNA<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<ul>\n<li>The CVE ID you want to discuss  <\/li>\n<li>The information you want to add, remove, or change within the CVE record  <\/li>\n<li>Why you want to change the information  <\/li>\n<li>Supporting evidence, usually in the form of a reference link<\/li>\n<\/ul>\n<p>Including publicly available reference links is important, as they justify the changes. Examples of reference links include:<\/p>\n<ul>\n<li>A publicly available vulnerability report, advisory, or proof-of-concept  <\/li>\n<li>A fix commit or release notes that describe a patch  <\/li>\n<li>An issue in the affected repository in which the maintainer discusses the vulnerability in their software with the community  <\/li>\n<li>A <a href=\"https:\/\/docs.github.com\/en\/code-security\/security-advisories\/working-with-global-security-advisories-from-the-github-advisory-database\/editing-security-advisories-in-the-github-advisory-database\">community contribution<\/a> pull request that suggests a change to the CVE&rsquo;s corresponding GitHub Security Advisory<\/li>\n<\/ul>\n<p>When submitting changes, keep in mind that the CNA isn&rsquo;t your only audience. Clear context around disclosure decisions and vulnerability details helps the broader developer and security community understand the risks and make informed decisions about mitigation.<\/p>\n<p>The time it takes for a CNA to respond may vary. <a href=\"https:\/\/www.cve.org\/ResourcesSupport\/AllResources\/CNARules#section_3-2_CNA_Administration\">Rules 3.2.4.1 and 3.2.4.2 of the CVE CNA rules<\/a> state:<\/p>\n<p>&ldquo;3.2.4.1 Subject to their respective CNA Scope Definitions, CNAs MUST respond in a timely manner to CVE ID assignment requests submitted through the CNA&rsquo;s public POC.<\/p>\n<p>3.2.4.2 CNAs SHOULD document their expected response times, including those for the public POC.&rdquo;<\/p>\n<p>The CNA rules establish firm timelines for assignment of CVE IDs to vulnerabilities that are already public knowledge. For CVE ID assignment or record publication in particular, <a href=\"https:\/\/www.cve.org\/ResourcesSupport\/AllResources\/CNARules#section_4-2_CVE_ID_Assignment\">section 4.2<\/a> and <a href=\"https:\/\/www.cve.org\/ResourcesSupport\/AllResources\/CNARules#section_4-5_CVE_Record_Management\">section 4.5<\/a> of the CVE CNA rules establish 72 hours as the time limit in which CNAs should issue CVE IDs or publish CVE records for publicly-known vulnerabilities. However, no such guidance exists for changing a CVE record.<\/p>\n<h2 id=\"what-if-the-cna-doesnt-respond-or-disagrees-with-me\" id=\"what-if-the-cna-doesnt-respond-or-disagrees-with-me\" ><a class=\"heading-link\" href=\"#what-if-the-cna-doesnt-respond-or-disagrees-with-me\">What if the CNA doesn&rsquo;t respond or disagrees with me?<span class=\"heading-hash pl-2 text-italic text-bold\" aria-hidden=\"true\"><\/span><\/a><\/h2>\n<p>If the CNA doesn&rsquo;t respond or you cannot reach an agreement about the content of the CVE record, the next step is to engage in the <a href=\"https:\/\/www.cve.org\/Resources\/General\/Policies\/CVE-Record-Dispute-Policy.pdf\">dispute process<\/a>.<\/p>\n<p><a href=\"https:\/\/www.cve.org\/Resources\/General\/Policies\/CVE-Record-Dispute-Policy.pdf\">The CVE Program Policy and Procedure for Disputing a CVE Record<\/a> provides details on how you may go about disputing a CVE record and escalating a dispute. The details of that process are beyond the scope of this post. However, if you end up disputing a CVE record, it&rsquo;s good to know who the root or top-level root of the CNA is that reviews the dispute.<\/p>\n<p>When viewing a CNA&rsquo;s partner page linked from <a href=\"https:\/\/www.cve.org\/PartnerInformation\/ListofPartners\">https:\/\/www.cve.org\/PartnerInformation\/ListofPartners<\/a>, you can find the CNA&rsquo;s root under the column &ldquo;Top-Level Root.&rdquo; For most CNAs, their root is the Top-Level Root, MITRE.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" loading=\"lazy\" src=\"https:\/\/github.blog\/wp-content\/uploads\/2025\/04\/Screenshot-2025-03-13-at-6.32.21%E2%80%AFPM.png?resize=1024%2C590\" alt=\"A screenshot of the cve.org entry for the CNA &ldquo;GitHub, Inc.&rdquo; A yellow rectangle is drawn around an entry in a table to draw attention to the two items in the table that are being discussed in the post. The left column contains the category &ldquo;Top-Level Root,&rdquo; and the right column contains the entry &ldquo;MITRE Corporation,&rdquo; with the text containing a link to a page about the MITRE Corporation.\" width=\"1024\" height=\"590\" class=\"alignnone size-full wp-image-86291 width-fit\"><\/p>\n<div class=\"post-content-cta\"><p><strong>Want to improve a CVE record <em>and<\/em> a CVE record&rsquo;s corresponding security advisory?<\/strong> Learn more about <a href=\"https:\/\/docs.github.com\/en\/code-security\/security-advisories\/working-with-global-security-advisories-from-the-github-advisory-database\/editing-security-advisories-in-the-github-advisory-database\">editing security advisories in the GitHub Advisory Database<\/a>.<\/p>\n<\/div>\n<\/body><\/html>\n","protected":false},"excerpt":{"rendered":"<p>Learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion.<\/p>\n","protected":false},"author":2303,"featured_media":85981,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_gh_post_show_toc":"yes","_gh_post_is_no_robots":"no","_gh_post_is_featured":"yes","_gh_post_is_excluded":"no","_gh_post_is_unlisted":"no","_gh_post_related_link_1":"","_gh_post_related_link_2":"","_gh_post_related_link_3":"","_gh_post_sq_img":"","_gh_post_sq_img_id":"","_gh_post_cta_title":"","_gh_post_cta_text":"","_gh_post_cta_link":"","_gh_post_cta_button":"Click Here to Learn More","_gh_post_recirc_hide":"no","_gh_post_recirc_col_1":"78957","_gh_post_recirc_col_2":"78959","_gh_post_recirc_col_3":"78961","_gh_post_recirc_col_4":"65316","_featured_video":"","_gh_post_additional_query_params":"","_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"{title}\n\n{excerpt}\n\n{url}","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_wpas_customize_per_network":false,"jetpack_post_was_ever_published":false,"_links_to":"","_links_to_target":""},"categories":[3332,67,91,3336],"tags":[3644,3645,3465,3643,3646,1915,3467],"coauthors":[3642],"class_list":["post-86286","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-maintainers","category-open-source","category-security","category-vulnerability-research","tag-cna","tag-community-contribution","tag-cve","tag-cve-numbering-authority","tag-cve-quality","tag-github-security-lab","tag-open-source-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.4 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>How to request a change to a CVE record - The GitHub Blog<\/title>\n<meta name=\"description\" content=\"Learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to request a change to a CVE record\" \/>\n<meta property=\"og:description\" content=\"Learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/\" \/>\n<meta property=\"og:site_name\" content=\"The GitHub Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-09T20:02:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/github.blog\/wp-content\/uploads\/2025\/03\/github_logo_invertocat_dark_5.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Shelby Cunningham\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Shelby Cunningham\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/\"},\"author\":{\"name\":\"Shelby Cunningham\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/b0ba24016891a5a68190e6c80e447c9c\"},\"headline\":\"How to request a change to a CVE record\",\"datePublished\":\"2025-04-09T20:02:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/\"},\"wordCount\":867,\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/github_logo_invertocat_dark_5.png?fit=1200%2C630\",\"keywords\":[\"CNA\",\"Community Contribution\",\"CVE\",\"CVE Numbering Authority\",\"CVE quality\",\"GitHub Security Lab\",\"open source security\"],\"articleSection\":[\"Maintainers\",\"Open Source\",\"Security\",\"Vulnerability research\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/\",\"url\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/\",\"name\":\"How to request a change to a CVE record - The GitHub Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/github_logo_invertocat_dark_5.png?fit=1200%2C630\",\"datePublished\":\"2025-04-09T20:02:44+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/b0ba24016891a5a68190e6c80e447c9c\"},\"description\":\"Learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/#primaryimage\",\"url\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/github_logo_invertocat_dark_5.png?fit=1200%2C630\",\"contentUrl\":\"https:\\\/\\\/github.blog\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/github_logo_invertocat_dark_5.png?fit=1200%2C630\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/how-to-request-a-change-to-a-cve-record\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/github.blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/github.blog\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Vulnerability research\",\"item\":\"https:\\\/\\\/github.blog\\\/security\\\/vulnerability-research\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"How to request a change to a CVE record\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/github.blog\\\/#website\",\"url\":\"https:\\\/\\\/github.blog\\\/\",\"name\":\"The GitHub Blog\",\"description\":\"Updates, ideas, and inspiration from GitHub to help developers build and design software.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/github.blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/github.blog\\\/#\\\/schema\\\/person\\\/b0ba24016891a5a68190e6c80e447c9c\",\"name\":\"Shelby Cunningham\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e4986996919eebeba4058ce8ed527872a9b09b55815ea02a167e008ff3ae65?s=96&d=mm&r=g0e3fcfe75a925e608df564bd76b4ba31\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e4986996919eebeba4058ce8ed527872a9b09b55815ea02a167e008ff3ae65?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a5e4986996919eebeba4058ce8ed527872a9b09b55815ea02a167e008ff3ae65?s=96&d=mm&r=g\",\"caption\":\"Shelby Cunningham\"},\"description\":\"Security Analyst, curator of the GitHub Advisory Database, and one of the members of the Security Lab responsible for issuing CVE IDs and publishing CVE records.\",\"url\":\"https:\\\/\\\/github.blog\\\/author\\\/shelbyc\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How to request a change to a CVE record - The GitHub Blog","description":"Learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/","og_locale":"en_US","og_type":"article","og_title":"How to request a change to a CVE record","og_description":"Learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion.","og_url":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/","og_site_name":"The GitHub Blog","article_published_time":"2025-04-09T20:02:44+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/github.blog\/wp-content\/uploads\/2025\/03\/github_logo_invertocat_dark_5.png","type":"image\/png"}],"author":"Shelby Cunningham","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Shelby Cunningham","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/#article","isPartOf":{"@id":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/"},"author":{"name":"Shelby Cunningham","@id":"https:\/\/github.blog\/#\/schema\/person\/b0ba24016891a5a68190e6c80e447c9c"},"headline":"How to request a change to a CVE record","datePublished":"2025-04-09T20:02:44+00:00","mainEntityOfPage":{"@id":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/"},"wordCount":867,"image":{"@id":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2025\/03\/github_logo_invertocat_dark_5.png?fit=1200%2C630","keywords":["CNA","Community Contribution","CVE","CVE Numbering Authority","CVE quality","GitHub Security Lab","open source security"],"articleSection":["Maintainers","Open Source","Security","Vulnerability research"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/","url":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/","name":"How to request a change to a CVE record - The GitHub Blog","isPartOf":{"@id":"https:\/\/github.blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/#primaryimage"},"image":{"@id":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/#primaryimage"},"thumbnailUrl":"https:\/\/github.blog\/wp-content\/uploads\/2025\/03\/github_logo_invertocat_dark_5.png?fit=1200%2C630","datePublished":"2025-04-09T20:02:44+00:00","author":{"@id":"https:\/\/github.blog\/#\/schema\/person\/b0ba24016891a5a68190e6c80e447c9c"},"description":"Learn how to identify which CVE Numbering Authority is responsible for the record, how to contact them, and what to include with your suggestion.","breadcrumb":{"@id":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/#primaryimage","url":"https:\/\/github.blog\/wp-content\/uploads\/2025\/03\/github_logo_invertocat_dark_5.png?fit=1200%2C630","contentUrl":"https:\/\/github.blog\/wp-content\/uploads\/2025\/03\/github_logo_invertocat_dark_5.png?fit=1200%2C630","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/github.blog\/security\/vulnerability-research\/how-to-request-a-change-to-a-cve-record\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/github.blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/github.blog\/security\/"},{"@type":"ListItem","position":3,"name":"Vulnerability research","item":"https:\/\/github.blog\/security\/vulnerability-research\/"},{"@type":"ListItem","position":4,"name":"How to request a change to a CVE record"}]},{"@type":"WebSite","@id":"https:\/\/github.blog\/#website","url":"https:\/\/github.blog\/","name":"The GitHub Blog","description":"Updates, ideas, and inspiration from GitHub to help developers build and design software.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/github.blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/github.blog\/#\/schema\/person\/b0ba24016891a5a68190e6c80e447c9c","name":"Shelby Cunningham","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a5e4986996919eebeba4058ce8ed527872a9b09b55815ea02a167e008ff3ae65?s=96&d=mm&r=g0e3fcfe75a925e608df564bd76b4ba31","url":"https:\/\/secure.gravatar.com\/avatar\/a5e4986996919eebeba4058ce8ed527872a9b09b55815ea02a167e008ff3ae65?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a5e4986996919eebeba4058ce8ed527872a9b09b55815ea02a167e008ff3ae65?s=96&d=mm&r=g","caption":"Shelby Cunningham"},"description":"Security Analyst, curator of the GitHub Advisory Database, and one of the members of the Security Lab responsible for issuing CVE IDs and publishing CVE records.","url":"https:\/\/github.blog\/author\/shelbyc\/"}]}},"jetpack_publicize_connections":[],"jetpack_shortlink":"https:\/\/wp.me\/pamS32-mrI","jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/github.blog\/wp-content\/uploads\/2025\/03\/github_logo_invertocat_dark_5.png?fit=1200%2C630","_links":{"self":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/86286","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/users\/2303"}],"replies":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/comments?post=86286"}],"version-history":[{"count":10,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/86286\/revisions"}],"predecessor-version":[{"id":86293,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/posts\/86286\/revisions\/86293"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media\/85981"}],"wp:attachment":[{"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/media?parent=86286"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/categories?post=86286"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/tags?post=86286"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/github.blog\/wp-json\/wp\/v2\/coauthors?post=86286"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}