PURL Expansion Working Group

The CPE machine-readable software identifier used by the CVE program for two decades has been included in fewer than 50% of published CVEs, making it extremely difficult to identify vulnerable components. Last October, the CVE program accepted PURL as an alternative identifier; PURL is superior to CPE in many ways. But a much wider effort is needed for PURL to become the predominant software identifier in CVE records. The PURL Expansion Working Group will make that effort.

About PURL Expansion Working Group

Project Information

Classification
Working Group
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.