API Reference
The vuln.mlab.sh CVE API - search, feeds, exports and OSV lookup.
Query Parameters
Keyword (product, vendor, CVE ID, free text).
""0-based page index.
0Results per page. Hard-capped at 100.
value <= 10020Filter by CVSS severity.
Value in
- "CRITICAL"
- "HIGH"
- "MEDIUM"
- "LOW"
Lower bound on published (YYYY-MM-DD).
Upper bound on published (YYYY-MM-DD).
If 1, exact-match the keyword instead of fuzzy.
0Value in
- 0
- 1
Response Body
application/json
curl -X GET "https://example.com/api/v1/cve"{ "total_results": 140, "results_per_page": 1, "start_index": 0, "cves": [ { "id": "CVE-2024-3094", "cvss_score": 10, "cvss_severity": "CRITICAL" } ]}curl -X GET "https://example.com/api/v1/cve/latest"{ "total_results": 140, "results_per_page": 1, "start_index": 0, "cves": [ { "id": "CVE-2024-3094", "cvss_score": 10, "cvss_severity": "CRITICAL" } ]}Query Parameters
Inclusive lower bound on published (YYYY-MM-DD).
Inclusive upper bound on published (YYYY-MM-DD). Must be >= dateStart.
Minimum CVSS base score. CVEs without a score are excluded.
0 <= value <= 100Response Body
application/json
curl -X GET "https://example.com/api/v1/cve/dump?dateStart=2024-01-01&dateEnd=2024-12-31"{ "error": "dateEnd must be >= dateStart"}curl -X GET "https://example.com/api/v1/cve/CVE-2024-3094"{ "id": "CVE-2024-3094", "description": "Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0…", "published": "2024-03-29T17:15:21.150", "last_modified": "2026-06-17T07:43:17.830", "status": "Modified", "cvss_score": 10, "cvss_severity": "CRITICAL", "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H", "cvss_breakdown": [ { "code": "AV", "name": "Attack Vector", "value_code": "N", "value": "Network" } ], "references": [ { "url": "https://access.redhat.com/security/cve/CVE-2024-3094", "source": "[email protected]", "tags": [ "Vendor Advisory" ] } ], "weaknesses": [ "CWE-506" ], "affected_products": [ "Tukaani Xz 5.6.0", "Tukaani Xz 5.6.1" ], "epss_score": null, "epss_percentile": null, "in_kev": false, "kev_date_added": null, "kev_due_date": null, "risk_score": 80}curl -X GET "https://example.com/api/v1/sources"[ { "name": "nvd", "priority": 0, "available": true, "tokens": 10, "cooldown_secs": 0, "requests": 22227, "successes": 18585, "rate_limited": 2252, "failures": 1390 }]curl -X GET "https://example.com/api/v1/stats"{ "critical": 30291, "high": 75462, "medium": 82017, "low": 3214, "total": 363360, "generated_at": 1783268841}curl -X GET "https://example.com/rss""<item>\n <title>[HIGH] CVE-2024-1234 (8.1)</title>\n <link>https://vuln.mlab.sh/cve/CVE-2024-1234</link>\n <description>...</description>\n <pubDate>Mon, 12 May 2025 00:00:00 GMT</pubDate>\n <guid>https://vuln.mlab.sh/cve/CVE-2024-1234</guid>\n</item>\n"curl -X GET "https://example.com/export/csv""CVE ID,CVSS Score,Severity,Published,Status,Description\nCVE-2021-44228,10.0,CRITICAL,2021-12-10,Analyzed,\"Apache Log4j2 ...\"\n"Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Either package.purl, or package.ecosystem + package.name (with optional top-level version). Free-text queries are rejected.
Response Body
application/json
curl -X POST "https://example.com/api/v2/query" \ -H "Content-Type: application/json" \ -d '{ "package": { "purl": "pkg:cargo/[email protected]" } }'{ "vulns": [ { "id": "GHSA-wcg3-cvx6-7396", "summary": "Potential segfault in the time crate", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L" } ], "affected": [ { "package": { "ecosystem": "crates.io", "name": "time", "purl": "pkg:cargo/time" }, "ranges": [ { "type": "SEMVER", "events": [ { "introduced": "0.1.0" }, { "fixed": "0.2.23" } ] } ] } ] } ]}Personal API token as Authorization: Bearer <token>. Generate one at /me/tokens. On /api/v2/scan it raises the quota to 25 scans/hour per token.
In: header
Query Parameters
HTTPS URL of a lockfile / SBOM.
uriForce the parser; auto sniffs from the URL then content.
"auto"Value in
- "auto"
- "npm"
- "cargo"
- "pip"
- "composer"
- "gem"
- "go"
- "cyclonedx"
- "mise"
Response Body
application/json
curl -X GET "https://example.com/api/v2/scan?url=https%3A%2F%2Fraw.githubusercontent.com%2Frust-lang%2Fcargo%2Fmaster%2FCargo.lock"{ "hash": "8a1564f1d99d2afa", "cached": false, "count": 2, "truncated": false, "logged_in": false, "ttl": 21600, "packages": [ { "ecosystem": "crates.io", "name": "time", "version": "0.1.44" }, { "ecosystem": "crates.io", "name": "serde", "version": "1.0.100" } ], "results": [ { "ok": true, "vulns": [ { "id": "GHSA-wcg3-cvx6-7396", "aliases": [ "CVE-2020-26235", "RUSTSEC-2020-0071" ] } ] }, { "ok": true, "vulns": [] } ]}Personal API token as Authorization: Bearer <token>. Generate one at /me/tokens. On /api/v2/scan it raises the quota to 25 scans/hour per token.
In: header
Query Parameters
Fetch this lockfile instead of reading the body (wins over a body url).
uri"auto"Value in
- "auto"
- "npm"
- "cargo"
- "pip"
- "composer"
- "gem"
- "go"
- "cyclonedx"
- "mise"
Name hint for a raw body (e.g. Cargo.lock).
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
curl -X POST "https://example.com/api/v2/scan" \ -H "Content-Type: application/json" \ -d '{ "packages": [ { "ecosystem": "crates.io", "name": "time", "version": "0.1.44" }, { "purl": "pkg:npm/[email protected]" } ] }'{ "hash": "8a1564f1d99d2afa", "cached": false, "count": 2, "truncated": false, "logged_in": false, "ttl": 21600, "packages": [ { "ecosystem": "crates.io", "name": "time", "version": "0.1.44" }, { "ecosystem": "crates.io", "name": "serde", "version": "1.0.100" } ], "results": [ { "ok": true, "vulns": [ { "id": "GHSA-wcg3-cvx6-7396", "aliases": [ "CVE-2020-26235", "RUSTSEC-2020-0071" ] } ] }, { "ok": true, "vulns": [] } ]}