OSV at https://api.osv.dev/v1 is Google's open vulnerability database, aggregating GitHub advisories, PyPI, Go, RustSec, and more in one schema.
None — no key, no signup. Every example runs as-is.
Full reference: https://google.github.io/osv.dev/api/
curl -X POST https://api.osv.dev/v1/query \
-H "Content-Type: application/json" \
-d '{"package": {"name": "lodash", "ecosystem": "npm"}, "version": "4.17.15"}'
{
"vulns": [
{
"id": "GHSA-29mw-wpgm-hmr9",
"summary": "Regular Expression Denial of Service (ReDoS) in lodash",
"aliases": [
"CVE-2020-28500"
],
"modified": "2025-09-29T21:12:31.102523Z",
"published": "2022-01-06T20:30:46Z",
"database_specific": {
"severity": "MODERATE",
"github_reviewed": true,
"github_reviewed_at": "2021-03-19T22:45:28Z",
"nvd_published_at": "2021-02-15T11:15:00Z",
"cwe_ids": [
"CWE-1333",
"CWE-400"
]
},
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28500"
},
{
"type": "WEB",
"url": "https://github.com/github/advisory-database/pull/6139"
}
],
"affected": [
{},
{}
],
"schema_version": "1.9.0",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
}
]
},
{
"id": "GHSA-35jh-r3h4-6jhm",
"summary": "Command Injection in lodash",
"details": "`lodash` versions prior to 4.17.21 are vulnerable to Command Injection via the template function.",
"aliases": [
"CVE-2021-23337",
"CVE-2026-4800"
],
"modified": "2026-09-10T03:49:04.067984836Z",
"published": "2021-05-06T16:05:51Z",
"database_specific": {
"github_reviewed": true,
"github_reviewed_at": "2021-03-31T23:59:26Z",
"nvd_published_at": "2021-02-15T13:15:00Z",
"cwe_ids": [
"CWE-77",
"CWE-94"
],
"severity": "HIGH"
},
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-23337"
},
{
"type": "WEB",
"url": "https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c"
}
],
"affected": [
{},
{}
],
"schema_version": "1.9.0",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
}
]
}
]
}
curl https://api.osv.dev/v1/vulns/GHSA-jfh8-c2jp-5v3q
{
"id": "GHSA-jfh8-c2jp-5v3q",
"summary": "Remote code injection in Log4j",
"aliases": [
"CVE-2021-44228"
],
"modified": "2025-10-22T19:37:02.616807Z",
"published": "2021-12-10T00:40:56Z",
"database_specific": {
"nvd_published_at": "2021-12-10T10:15:00Z",
"cwe_ids": [
"CWE-20",
"CWE-400"
],
"severity": "CRITICAL",
"github_reviewed": true,
"github_reviewed_at": "2021-12-10T00:40:41Z"
},
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
},
{
"type": "WEB",
"url": "https://github.com/apache/logging-log4j2/pull/608"
}
],
"affected": [
{
"package": {
"name": "org.apache.logging.log4j:log4j-core",
"ecosystem": "Maven",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"type": "ECOSYSTEM"
}
],
"versions": [
"2.13.0",
"2.13.1"
],
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-jfh8-c2jp-5v3q/GHSA-jfh8-c2jp-5v3q.json"
}
},
{
"package": {
"name": "org.apache.logging.log4j:log4j-core",
"ecosystem": "Maven",
"purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
},
"ranges": [
{
"type": "ECOSYSTEM"
}
],
"versions": [
"2.0",
"2.0-beta9"
],
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-jfh8-c2jp-5v3q/GHSA-jfh8-c2jp-5v3q.json"
}
}
],
"schema_version": "1.9.0",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H"
}
]
}