mlab docs

API Reference

The vuln.mlab.sh CVE API - search, feeds, exports and OSV lookup.

GET
/api/v1/cve

Query Parameters

q?string

Keyword (product, vendor, CVE ID, free text).

Default""
page?integer

0-based page index.

Default0
limit?integer

Results per page. Hard-capped at 100.

Rangevalue <= 100
Default20
severity?string

Filter by CVSS severity.

Value in

  • "CRITICAL"
  • "HIGH"
  • "MEDIUM"
  • "LOW"
dateStart?string

Lower bound on published (YYYY-MM-DD).

dateEnd?string

Upper bound on published (YYYY-MM-DD).

exact?integer

If 1, exact-match the keyword instead of fuzzy.

Default0

Value in

  • 0
  • 1

Response Body

application/json

curl -X GET "https://example.com/api/v1/cve"
{  "total_results": 140,  "results_per_page": 1,  "start_index": 0,  "cves": [    {      "id": "CVE-2024-3094",      "cvss_score": 10,      "cvss_severity": "CRITICAL"    }  ]}
GET
/api/v1/cve/latest

Response Body

application/json

curl -X GET "https://example.com/api/v1/cve/latest"
{  "total_results": 140,  "results_per_page": 1,  "start_index": 0,  "cves": [    {      "id": "CVE-2024-3094",      "cvss_score": 10,      "cvss_severity": "CRITICAL"    }  ]}
GET
/api/v1/cve/dump

Query Parameters

dateStart*string

Inclusive lower bound on published (YYYY-MM-DD).

dateEnd*string

Inclusive upper bound on published (YYYY-MM-DD). Must be >= dateStart.

minCvss?number

Minimum CVSS base score. CVEs without a score are excluded.

Range0 <= value <= 10
Default0

Response Body

application/json

curl -X GET "https://example.com/api/v1/cve/dump?dateStart=2024-01-01&dateEnd=2024-12-31"
{  "error": "dateEnd must be >= dateStart"}
GET
/api/v1/cve/{id}

Path Parameters

id*string

A CVE identifier (CVE-YYYY-NNNN+).

Response Body

application/json

curl -X GET "https://example.com/api/v1/cve/CVE-2024-3094"
{  "id": "CVE-2024-3094",  "description": "Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0…",  "published": "2024-03-29T17:15:21.150",  "last_modified": "2026-06-17T07:43:17.830",  "status": "Modified",  "cvss_score": 10,  "cvss_severity": "CRITICAL",  "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",  "cvss_breakdown": [    {      "code": "AV",      "name": "Attack Vector",      "value_code": "N",      "value": "Network"    }  ],  "references": [    {      "url": "https://access.redhat.com/security/cve/CVE-2024-3094",      "source": "[email protected]",      "tags": [        "Vendor Advisory"      ]    }  ],  "weaknesses": [    "CWE-506"  ],  "affected_products": [    "Tukaani Xz 5.6.0",    "Tukaani Xz 5.6.1"  ],  "epss_score": null,  "epss_percentile": null,  "in_kev": false,  "kev_date_added": null,  "kev_due_date": null,  "risk_score": 80}
GET
/api/v1/sources

Response Body

application/json

curl -X GET "https://example.com/api/v1/sources"
[  {    "name": "nvd",    "priority": 0,    "available": true,    "tokens": 10,    "cooldown_secs": 0,    "requests": 22227,    "successes": 18585,    "rate_limited": 2252,    "failures": 1390  }]
GET
/api/v1/stats

Response Body

application/json

curl -X GET "https://example.com/api/v1/stats"
{  "critical": 30291,  "high": 75462,  "medium": 82017,  "low": 3214,  "total": 363360,  "generated_at": 1783268841}
GET
/rss

Response Body

application/rss+xml

curl -X GET "https://example.com/rss"
"<item>\n  <title>[HIGH] CVE-2024-1234 (8.1)</title>\n  <link>https://vuln.mlab.sh/cve/CVE-2024-1234</link>\n  <description>...</description>\n  <pubDate>Mon, 12 May 2025 00:00:00 GMT</pubDate>\n  <guid>https://vuln.mlab.sh/cve/CVE-2024-1234</guid>\n</item>\n"
GET
/export/csv

Query Parameters

q?string

Keyword used by the underlying search.

Response Body

text/csv

curl -X GET "https://example.com/export/csv"
"CVE ID,CVSS Score,Severity,Published,Status,Description\nCVE-2021-44228,10.0,CRITICAL,2021-12-10,Analyzed,\"Apache Log4j2 ...\"\n"
POST
/api/v2/query

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

Either package.purl, or package.ecosystem + package.name (with optional top-level version). Free-text queries are rejected.

Response Body

application/json

curl -X POST "https://example.com/api/v2/query" \  -H "Content-Type: application/json" \  -d '{    "package": {      "purl": "pkg:cargo/[email protected]"    }  }'
{  "vulns": [    {      "id": "GHSA-wcg3-cvx6-7396",      "summary": "Potential segfault in the time crate",      "severity": [        {          "type": "CVSS_V3",          "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"        }      ],      "affected": [        {          "package": {            "ecosystem": "crates.io",            "name": "time",            "purl": "pkg:cargo/time"          },          "ranges": [            {              "type": "SEMVER",              "events": [                {                  "introduced": "0.1.0"                },                {                  "fixed": "0.2.23"                }              ]            }          ]        }      ]    }  ]}
Empty
Empty
Empty
GET
/api/v2/scan

Authorization

AuthorizationBearer <token>

Personal API token as Authorization: Bearer <token>. Generate one at /me/tokens. On /api/v2/scan it raises the quota to 25 scans/hour per token.

In: header

Query Parameters

url*string

HTTPS URL of a lockfile / SBOM.

Formaturi
format?string

Force the parser; auto sniffs from the URL then content.

Default"auto"

Value in

  • "auto"
  • "npm"
  • "cargo"
  • "pip"
  • "composer"
  • "gem"
  • "go"
  • "cyclonedx"
  • "mise"

Response Body

application/json

curl -X GET "https://example.com/api/v2/scan?url=https%3A%2F%2Fraw.githubusercontent.com%2Frust-lang%2Fcargo%2Fmaster%2FCargo.lock"
{  "hash": "8a1564f1d99d2afa",  "cached": false,  "count": 2,  "truncated": false,  "logged_in": false,  "ttl": 21600,  "packages": [    {      "ecosystem": "crates.io",      "name": "time",      "version": "0.1.44"    },    {      "ecosystem": "crates.io",      "name": "serde",      "version": "1.0.100"    }  ],  "results": [    {      "ok": true,      "vulns": [        {          "id": "GHSA-wcg3-cvx6-7396",          "aliases": [            "CVE-2020-26235",            "RUSTSEC-2020-0071"          ]        }      ]    },    {      "ok": true,      "vulns": []    }  ]}
Empty
Empty
Empty
POST
/api/v2/scan

Authorization

AuthorizationBearer <token>

Personal API token as Authorization: Bearer <token>. Generate one at /me/tokens. On /api/v2/scan it raises the quota to 25 scans/hour per token.

In: header

Query Parameters

url?string

Fetch this lockfile instead of reading the body (wins over a body url).

Formaturi
format?string
Default"auto"

Value in

  • "auto"
  • "npm"
  • "cargo"
  • "pip"
  • "composer"
  • "gem"
  • "go"
  • "cyclonedx"
  • "mise"
filename?string

Name hint for a raw body (e.g. Cargo.lock).

Request Body

TypeScript Definitions

Use the request body type in TypeScript.

Response Body

application/json

curl -X POST "https://example.com/api/v2/scan" \  -H "Content-Type: application/json" \  -d '{    "packages": [      {        "ecosystem": "crates.io",        "name": "time",        "version": "0.1.44"      },      {        "purl": "pkg:npm/[email protected]"      }    ]  }'
{  "hash": "8a1564f1d99d2afa",  "cached": false,  "count": 2,  "truncated": false,  "logged_in": false,  "ttl": 21600,  "packages": [    {      "ecosystem": "crates.io",      "name": "time",      "version": "0.1.44"    },    {      "ecosystem": "crates.io",      "name": "serde",      "version": "1.0.100"    }  ],  "results": [    {      "ok": true,      "vulns": [        {          "id": "GHSA-wcg3-cvx6-7396",          "aliases": [            "CVE-2020-26235",            "RUSTSEC-2020-0071"          ]        }      ]    },    {      "ok": true,      "vulns": []    }  ]}
Empty
Empty
Empty