One part of CVE assignment I always found odd is that you practically *have to* hand over data to a US organization to get a CVE. Now with the entire #UnplugTrump stuff going on, maybe its a good time to advocate for a European CNA of Last Resort.
Currently only 3 CNA-LR exist and they are all US based (MITRE, CISA, and Red Hat).