A public record, prepared responsibly.
A controlled path from validated technical evidence to coordinated publication.
root@hckrt:~# Hackrate CVE Numbering Authority
Hackrate is Hungary’s first CVE Numbering Authority (CNA). We help companies and security researchers assess CVE eligibility, prepare accurate CVE Record data, and coordinate publication for vulnerabilities within our approved scope.
A controlled path from validated technical evidence to coordinated publication.
What CNA status means
As a CVE Numbering Authority, Hackrate can assign CVE IDs and publish corresponding CVE Records for eligible vulnerabilities within its approved scope.
Reserve and assign a unique CVE ID when the vulnerability meets CVE Program requirements, falls within Hackrate’s scope, and is not already covered by an existing record.
Structure the public record with a clear vulnerability description, affected products and versions, references, credits, and additional technical data where appropriate.
Align the CVE Record with vendor approval, remediation progress, the public advisory, and the agreed disclosure timeline.
The coordination process
Hackrate customers can initiate the process from an eligible report in Resolved status. External companies and researchers can submit an initial request with the affected vendor, product, report status, and disclosure context.
Hackrate assesses whether the issue represents a CVE-eligible vulnerability, whether Hackrate is the appropriate CNA, and whether an existing or reserved CVE ID may already cover the same issue.
Our team reviews the technical evidence and prepares the proposed CVE Record data, including affected products and versions, the vulnerability description, references, credits, remediation status, and optional enrichment such as CWE or CVSS information where appropriate.
The affected company or program owner reviews the proposed public wording and agrees the disclosure timeline. A CVE ID may be reserved during this coordination phase, while sensitive details remain private until the agreed publication point.
Once the vulnerability is disclosure-ready and the public content has been approved, Hackrate coordinates publication of the CVE Record and the related public advisory. If relevant facts change later, the CVE Record can be updated in accordance with CVE Program rules.
Who we support
The path differs by audience, but the objective is the same: an eligible, validated, non-duplicate vulnerability record published through a responsible and coordinated disclosure process.
Hackrate customers have the most integrated route to CVE coordination.
For an eligible report in Resolved status, an authorized customer user can request CVE support directly from the report. The platform generates a first draft from the validated report data, which is then reviewed by Hackrate. The customer reviews and approves the public wording and disclosure timing. Once approved, Hackrate coordinates the public Hacktivity advisory and the corresponding CVE Record using only the information authorized for disclosure.
You do not need to operate an existing Hackrate program to ask for CVE coordination support. We can assess whether a vulnerability may fall within Hackrate’s CNA scope, review the available technical evidence, support record preparation, and coordinate the process through a structured Hackrate workflow.
We welcome requests from security researchers and penetration testers who have discovered a vulnerability and want to pursue responsible CVE publication.
To evaluate the request, we need a reproducible technical report, clear affected product and version information, evidence that the affected vendor has been contacted, and an agreed path toward remediation and public disclosure. A public advisory does not need to exist before CVE coordination begins, but an appropriate public reference must be ready when the CVE Record is published.
CVE support and the Cyber Resilience Act
The Cyber Resilience Act requires manufacturers of products with digital elements to put in place and enforce a coordinated vulnerability disclosure policy and to maintain processes for handling vulnerabilities reported from internal and external sources.
Hackrate managed VDP provides a structured reporting channel, technical validation, researcher communication, traceability, and optional CVE coordination when a public identifier is appropriate.
FAQ
Straight answers about eligibility, timing, scope, and responsible publication.
A CVE ID is a unique identifier assigned to a publicly disclosed cybersecurity vulnerability. It helps vendors, researchers, security teams, tools, and vulnerability databases refer to the same issue consistently.
A CVE Numbering Authority, or CNA, is an organization authorized by the CVE Program to assign CVE IDs and publish corresponding CVE Records within a defined scope.
No, Hackrate can assign CVE IDs only when the vulnerability is eligible, falls within Hackrate’s approved CNA scope, is not a duplicate, and is not more appropriately handled by another CNA.
CVE coordination should normally begin before public disclosure.
A CVE ID may be reserved during the coordination process. However, an appropriate public advisory or reference must be prepared for publication with the CVE Record.
No. Hackrate customers benefit from the most integrated workflow, but companies and security researchers outside the platform may also request support.
Yes. Researchers and penetration testers may request support for vulnerabilities they have discovered.
Hackrate will normally require a reproducible technical report, affected product and version information, evidence of vendor engagement, and an agreed public disclosure path.
No. CVE creation is optional and must be explicitly requested. The vulnerability must also pass Hackrate’s scope, eligibility, validation, duplication, and disclosure checks.
No. New vulnerabilities should be submitted through the relevant Hackrate program, vulnerability disclosure channel, or secure reporting process.
The timeline depends on technical validation, vendor responsiveness, remediation progress, CNA scope, duplication checks, and the agreed public disclosure date. Hackrate does not publish a CVE Record before the required coordination and approval steps are complete.
Whether you manage vulnerability reports in Hackrate, represent an affected company, or discovered the vulnerability as a security researcher, our team can help assess the appropriate next step. We review scope and eligibility before any public disclosure takes place.
Request CVE SupportOur platform helps companies to identify software vulnerabilities in a cost-efficient way. It provides a secure and centralized view of ethical hacking projects for your company.
US Patent Applied for HackGATE #63/645,845
May 29 • 13 min read
Jan 13 • 5 min read ★
Jan 05 • 4 min read