The CVSS SIG is currently evaluating updates to the CVSS JSON representation to ensure better validation, which is a blocker for CVSS v4.0 inclusion in CSAF 2.1.
The new draft representation is here: https://www.first.org/cvss/cvss-v4.0.rev.json
I wanted to ensure that moving the CVSS JSON representation to this form wouldn't break existing data in the CVE JSON schema. Can someone from the CVE side check?
Thanks!