The vulnerability record namespace
A vulnerability record identifier that says who assigned it
GAVR is a namespace for vulnerability records. Every identifier is permanent, resolves to a signed record, and names the body accountable for what it says.
01 — DEFINITION
What an identifier is
A permanent public reference to one vulnerability record. It is never reused and never reassigned, so a citation written today still points at the same record in ten years.
Who assigns them
Accredited bodies, listed in the directory here. Each declares the scope it may assign within, and each is vouched for by a body above it.
Why it is checkable
Every record carries its author's signature and this registry's countersignature over the pair. The registry's key is published separately, so verification never depends on trusting the record itself.
02 — LOOKUP
Resolve an identifier
Paste a GAVR you were given. Letters that are easy to confuse when read aloud or copied off paper are folded automatically.
03 — PROVENANCE
Two kinds of identifier, and the difference matters
They share a lookup and a schema. They do not share provenance, and nothing on this site will present them as if they did.
| PROPERTY | GAVR-A7K2QXR8 | GAVLR-42-7-A7K2QX |
|---|---|---|
| Issued by | A body this registry admitted, after review. | Whoever runs that local registry, at their own discretion. |
| In this ledger | Yes. The allocation is recorded here and never reissued. | No, and never will be. |
| Resolving it | Resolves here, returning the record and both signatures. | Follow the delegation path in the identifier to the registry that issued it. |
| What it tells you | A named accountable body stands behind the record, and you can check that without asking anyone. | That somebody assigned it to themselves. Whether to trust it is your judgement. |