services / cve-lookup
utilityoperational · 1 ms
CVE and Package Vulnerability Lookup
Look up a vulnerability by CVE or GHSA id (NVD: description, CVSS score and vector, CWE, CISA known-exploited flag; OSV: affected packages and fixed versions) or check a package version for known vulnerabilities via OSV.dev (npm, PyPI, Maven, Go, crates.io, RubyGems, NuGet, Packagist, Debian ...). Params: cve_id, or package + ecosystem (+ version, recommended), limit (default 20).
Run free trial ↗3 free calls per day with the example input. Paid: $0.003 USDC, no limit.
Call it
Input
| Field | Type | Description |
|---|---|---|
| cve_id | string | CVE-2021-44228 or GHSA-xxxx-xxxx-xxxx |
| package | string | |
| ecosystem | string | OSV ecosystem name, case sensitive: npm, PyPI, Maven, Go, crates.io, RubyGems, NuGet, Packagist |
| version | string | |
| limit | integer = 20 |
Output
| Field | Type | Description |
|---|---|---|
| query | object | |
| count | integer | |
| vulnerable | boolean | |
| vulnerabilities | array | |
| source | string | |
| checked_at | string |
Example response (data)
{
"query": {
"package": "lodash",
"ecosystem": "npm",
"version": "4.17.15"
},
"count": 6,
"vulnerable": true,
"vulnerabilities": [
{
"id": "GHSA-29mw-wpgm-hmr9",
"aliases": [
"CVE-2020-28500"
],
"summary": "Regular Expression Denial of Service (ReDoS) in lodash",
"severity": "MODERATE",
"cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"cwe": [
"CWE-1333",
"CWE-400"
],
"published": "2022-01-06",
"affected": [
{
"ecosystem": "npm",
"package": "lodash",
"ranges": [
{
"introduced": "4.0.0",
"fixed": "4.17.21",
"last_affected": null
}
]
},
{
"ecosystem": "npm",
"package": "lodash-es",
"ranges": [
{
"introduced": "4.0.0",
"fixed": "4.17.21",
"last_affected": null
}
]
}
],
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2020-28500",
"https://github.com/github/advisory-database/pull/6139"
],
"url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9"
}
],
"source": "OSV.dev",
"checked_at": "2026-10-06T14:30:56.665Z"
}