{
  "node_id": "cve-program-cna-record-format-5",
  "title": "CVE Program with CNA Hierarchy and Record Format 5.2.0 (CISA-Sponsored, MITRE Secretariat, 400+ CVE Numbering Authorities, JSON Schema, ADPs, CVE Services REST API)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-06-03",
  "bluf": "The Common Vulnerabilities and Exposures (CVE) Program is the canonical international vulnerability identifier system sponsored by the United States Cybersecurity and Infrastructure Security Agency (CISA) with The MITRE Corporation serving as the program Secretariat. Each CVE record is identified by a CVE ID in the format CVE-YYYY-NNNNN (year plus arbitrary-length sequence number) and represents a single publicly disclosed vulnerability. The program is governed by the CVE Board with operational governance through Working Groups including the CVE Quality Working Group (QWG). The CVE Record Format JSON Schema is maintained at github.com/CVEProject/cve-schema; the current production release is version 5.2.0 dated 29 October 2025 on the main branch. CVE Records use a cveMetadata block (cveId, assignerOrgId, state PUBLISHED or REJECTED or RESERVED, datePublished, dateUpdated) and one or more container blocks: the cna container submitted by the assigning CNA (containing affected product list with vendor/product/versions and version status affected/unaffected/unknown, descriptions in multiple languages, references with tags, problemTypes referencing CWE entries, metrics with CVSS v2/v3.0/v3.1/v4.0 scores) and optional adp containers from Authorized Data Publishers (CISA-ADP being the canonical ADP enriching records with CISA KEV and SSVC data). CVE Numbering Authorities are organisations authorised to assign CVE IDs and publish records: there are over 400 CNAs globally including Root CNAs (MITRE for the main pool), Top-Level Root CNAs (CISA-CERT/CC and JPCERT/CC), regional Root CNAs, vendor CNAs (Microsoft, Apple, Google, Cisco, Oracle, Red Hat, etc.), open-source project CNAs (GitHub, Linux Kernel, npm), bug-bounty CNAs (HackerOne, Bugcrowd), and CNA-LR (Last Resort) operated by MITRE for vulnerabilities outside other CNA scopes. The CVE Services REST API at cveawg.mitre.org handles ID reservation, record submission, and lookup; the canonical public view is cve.org and the legacy MITRE CVE List archive remains accessible at cve.mitre.org.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "program_basis",
      "key_institutions",
      "cve_record_format_5_x",
      "cna_container_fields",
      "adp_container_and_cisa_adp",
      "cna_hierarchy_roles",
      "cve_services_rest_api",
      "cve_to_cwe_problemtypes_mapping",
      "cve_to_nvd_enrichment_pipeline",
      "industry_mapping"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "us-cisa-kev-catalog",
    "us-cisa-known-exploited-vulnerabilities-bod-22-01",
    "mitre-cwe-top-25-2024-most-dangerous-weaknesses",
    "oasis-stix-2-1-structured-threat-information"
  ],
  "primary_citations_count": 8
}