Reserved, public, and unpublished.
What this site counts, why the CVE Program's own term is the right one for it, and what is being asked for.
A Reserved but Public CVE ID is one a CNA has reserved and that appears in a public advisory, while the CVE Record itself is still unpublished. Anyone pulling the CVE List sees nothing. The advisory is already out there.
The term is the CVE Program's own. Its glossary definition reads:
A CVE ID in the “Reserved” state that is referenced in one or more public sources but for which a CVE Record has not been published.
RBP Policy v2.0.0, approved by the CVE Board on 13 August 2026, expects a record within 72 hours of disclosure, and sets out a real process: a Root notifies the CNA with a remediation timeline, CNAs must prioritise requests to publish critical RBPs, and repeat failures escalate up to decertification. That process runs inside the Program and is not visible in public data, so this site reports the state rather than the response to it.
The state itself is observable, and the CVE Services API will confirm it. What it
will not tell you is who reserved the ID:
"owning_cna": "[REDACTED]". CNA Rule 4.5.1.7 both permits and limits
naming, and it binds the Secretariat rather than anyone else:
The Secretariat MAY publicly identify the CNA who reserved the CVE ID 24 hours after a CVE ID has been Publicly Disclosed. Otherwise, the Secretariat SHOULD NOT publicly identify the CNA until the CVE Record has been published.
So this site lists the identifier and the advisories it appears in, and leaves attribution to the Program. Ownership can be estimated from public data, and this version does not publish those estimates: the same reasoning that recovers an owner for a referenced ID would work across the whole reserved space, which is a good reason for the redaction to stay as it is.
To report a vulnerability in this site's own code, use a private security advisory.