PURL Expansion Working Group

The CPE machine-readable software identifier used by the CVE program for two decades has been included in fewer than 50% of published CVEs, making it extremely difficult to identify vulnerable components. Last October, the CVE program accepted PURL as an alternative identifier; PURL is superior to CPE in many ways. But a much wider effort is needed for PURL to become the predominant software identifier in CVE records. The PURL Expansion Working Group will make that effort.

About PURL Expansion Working Group

Exploitation of software vulnerabilities is responsible for more than one third of successful cyberattacks; that share is rapidly increasing. The only way to prevent these attacks is for software users to learn of vulnerabilities in the software they use and patch those vulnerabilities. The CVE database is by far the largest listing of software vulnerabilities.

However, simply listing a new vulnerability isn’t helpful if the listing doesn’t include a machine-readable identifier for the vulnerable software package(s). Since February 2024, less than 50% of new CVE records have included such an identifier; starting this year, that share fell to less than 25%. Thus, a search for a product in the National Vulnerability Database (NVD) today on average lists no more than 25% of vulnerabilities reported for that product in 2026.

This problem is due to flaws in the CPE software identifier that the CVE program has used for two decades. Last October, the program accepted PURL as an alternative identifier; PURL is superior to CPE in many ways. But a much wider effort is needed for PURL to become the predominant software identifier in CVE records. The PURL Expansion Working Group will make that effort.

The Mission Statement says that OWASP’s “goal is to empower developers and organizations to develop, purchase, and maintain software that can be trusted by making security visible and actionable.” Due to the lack of machine-readable software identifiers in CVE records, threats due to newly identified software vulnerabilities are neither visible nor actionable by software users. Ensuring widespread use of PURL in the CVE ecosystem is probably the most effective way to meet those threats head on.

Project Information

Classification
Working Group
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.