What CVE Program with CNA Hierarchy and Record Format 5.2.0 (CISA-Sponsored, MITRE Secretariat, 400+ CVE Numbering Authorities, JSON Schema, ADPs, CVE Services REST API) requires
The Common Vulnerabilities and Exposures (CVE) Program is the canonical international vulnerability identifier system sponsored by the United States Cybersecurity and Infrastructure Security Agency (CISA) with The MITRE Corporation serving as the program Secretariat. Each CVE record is identified by a CVE ID in the format CVE-YYYY-NNNNN (year plus arbitrary-length sequence number) and represents a single publicly disclosed vulnerability. The program is governed by the CVE Board with operational governance through Working Groups including the CVE Quality Working Group (QWG). The CVE Record Format JSON Schema is maintained at github.com/CVEProject/cve-schema; the current production release is version 5.2.0 dated 29 October 2025 on the main branch. CVE Records use a cveMetadata block (cveId, assignerOrgId, state PUBLISHED or REJECTED or RESERVED, datePublished, dateUpdated) and one or more container blocks: the cna container submitted by the assigning CNA (containing affected product list with vendor/product/versions and version status affected/unaffected/unknown, descriptions in multiple languages, references with tags, problemTypes referencing CWE entries, metrics with CVSS v2/v3.0/v3.1/v4.0 scores) and optional adp containers from Authorized Data Publishers (CISA-ADP being the canonical ADP enriching records with CISA KEV and SSVC data). CVE Numbering Authorities are organisations authorised to assign CVE IDs and publish records: there are over 400 CNAs globally including Root CNAs (MITRE for the main pool), Top-Level Root CNAs (CISA-CERT/CC and JPCERT/CC), regional Root CNAs, vendor CNAs (Microsoft, Apple, Google, Cisco, Oracle, Red Hat, etc.), open-source project CNAs (GitHub, Linux Kernel, npm), bug-bounty CNAs (HackerOne, Bugcrowd), and CNA-LR (Last Resort) operated by MITRE for vulnerabilities outside other CNA scopes. The CVE Services REST API at cveawg.mitre.org handles ID reservation, record submission, and lookup; the canonical public view is cve.org and the legacy MITRE CVE List archive remains accessible at cve.mitre.org.
Pillar: Cybersecurity · Authority: CVE Program (CISA sponsor; The MITRE Corporation Secretariat) · Version: 1.0.0 · Last updated:
Primary source: https://github.com/CVEProject/cve-schema
SHA-256 integrity: ffea2fa9e91befb9f4062ce73adc1096c7824acd57b4df2974ac3b7c8b1ce25f
Primary Citations — 8 traced to source
- CVE Program, sponsored by the United States Cybersecurity and Infrastructure Security Agency (CISA) with The MITRE Corporation as the program Secretariat; canonical public site at cve.org; CVE Record Format JSON Schema at github.com/CVEProject/cve-schema; current production schema version 5.2.0 dated 29 October 2025.
- CVE Quality Working Group (QWG) governance: 'CVE Board members, Representatives from CVE Numbering Authorities (CNAs), Authorized Data Publishers (ADPs), CVE Secretariat staff (currently MITRE Corporation)'; QWG Co-Chairs Chris Coffin (MITRE), MegaZone (F5), David Waltermire (GSA FedRAMP).
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/cve-program-cna-record-format-5.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/cve-program-cna-record-format-5.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/cve-program-cna-record-format-5
- Back to registry: Browse all 10,108 compliance nodes