Contacting the CVE Program

This page is maintained by the CVE Program Secretariat at The MITRE Corporation.

Community Notice: The CVE Program has recently introduced this contact page as an upgrade to the legacy cveform.mitre.org webpage. (Over time, additional web forms for other purposes will be added here.) If you experience difficulty in using this refreshed version, you can visit the legacy web form instead. We are operating the two sites in parallel for now, and will see your request either way.

Choose a Web Form

For information about CVE request/publication practices at MITRE's CNA of Last Resort, visit the MITRE CNA-LR website.
Program Secretariat

General Support (formerly "Other")

For questions or comments about the CVE Program, when no other linked web form is a better fit, this should be selected. The CVE Program Secretariat can route your request appropriately depending on its context. (This was labeled Other in the legacy web form.)

MITRE CNA-LR

CVE ID Requests

Here you can make new requests to MITRE for CVE IDs, update your CVE ID requests, request initial publication to the CVE List, or suggest updates to the CVE List. This is open to product Suppliers and to other vulnerability finders.

Program Secretariat

Join a Working Group

Here you can apply to join a CVE Program Working Group. In some cases, a group is open to all community members who can contribute to moving the CVE Program forward (others are for more specialized aspects of the CVE Program).

Contributing Organizations

Domain Verification

When an organization, rather than an individual, is contributing to CVE, we may ask for a simple verification in DNS that associates your organization's domain name. You can review this with your organization's DNS administrator.

Program Secretariat

Register to Become a CNA

Here, an organization can initially record its interest in obtaining the CNA role, to facilitate reporting many vulnerabilities for the CVE List. A new CNA can be located under the MITRE Top-Level Root (TL-Root) or under any other Root or TL-Root.

Program Secretariat

Report a Reserved But Public (RBP) CVE ID

Occasionally, a CVE ID is publicly used (e.g., in a published security advisory) but the CVE Record data is not yet available on cve.org because of a publication delay by the CNA. Please report any here.