GCVE BCP-12: A Standard Sighting Format for Vulnerabilities

GCVE BCP-12: A Standard Sighting Format for Vulnerabilities

August 1, 2026

 #GCVE#Sighting#CTI#vulnerability-management#open-source

We are pleased to announce the publication of GCVE BCP-12, a standard format for recording and exchanging vulnerability sightings.

The BCP is based on the existing sighting format implemented in Vulnerability-Lookup, which has already been used operationally over the past months. By standardising this proven format, BCP-12 aims to facilitate interoperability between vulnerability-management platforms, security tools, feeds and analysis systems.

Its design draws on years of experience with the limitations of sighting models in various CTI format, as well as the operational implementation of sightings in the MISP standard format. BCP-12 has a deliberately strong focus on vulnerabilities and on supporting the wide range of sighting use cases encountered in vulnerability management.

These include:

  • mentions and observations of vulnerabilities;
  • analyst confirmation or rejection;
  • publication of proofs of concept;
  • observed or explicitly unobserved exploitation;
  • successful or unsuccessful patching.

A sighting is treated as an assertion made by a specific observer at a particular point in time—not as a universal statement about a vulnerability. Different observers can therefore publish complementary or even conflicting sightings based on their respective environments, evidence and perspectives.

BCP-12 keeps the core format small and compatible with existing Vulnerability-Lookup implementations, while providing a separate extension mechanism for additional information such as confidence, evidence, observation scope, affected assets and external identifiers.

The specification is now available for public review:

https://gcve.eu/bcp/gcve-bcp-12/

Feedback, implementation experience and contributions are very welcome via https://discourse.ossbase.org/t/gcve-bcp-12-sighting-format/1085/6.