Vulnerability-Lookup 6.1.0 is out. The highlights:

  • CNA roots. The CVE Program hierarchy is now part of the platform. The assigner search accepts root:<name> to select every CNA under a root, the vulnerability page shows the assigner’s root, and a new dashboard tab lists the latest vulnerabilities of each root with per-root RSS/Atom feeds.
  • CNA activity report. One page summarizing everything your local CNA/GNA did over a date range: reservations, publications, KEV entries, sightings, disclosures, comments, bundles and registrations. Charts included, Markdown export too.
  • CPE Editor integration. The vulnerability page checks CPE names against the collaborative catalogue of the GCVE project (cpe.gcve.eu) and lets you propose missing vendors and products from a pre-filled form.

Also inside: sighting summaries on bundles, a Markdown export of recent vulnerabilities, the CVE Program bundle warning on flagged records, a KEV publication activity grid, frontend libraries managed with npm, and a batch of security and storage fixes.

Upgrading requires Node.js >= 18, a PostgreSQL migration and gcve >= 0.13.0. Instances that tuned kvrocks.conf should read the storage fix before restarting.

Full details on the blog: https://www.vulnerability-lookup.org/2026/09/02/vulnerability-lookup-6-1-0

Source: https://github.com/vulnerability-lookup/vulnerability-lookup