How to hit the OSV (Open Source Vulnerabilities) API

OSV at https://api.osv.dev/v1 is Google's open vulnerability database, aggregating GitHub advisories, PyPI, Go, RustSec, and more in one schema.

Authentication

None — no key, no signup. Every example runs as-is.

Full reference: https://google.github.io/osv.dev/api/

Vulnerabilities for a package version

curl -X POST https://api.osv.dev/v1/query \
  -H "Content-Type: application/json" \
  -d '{"package": {"name": "lodash", "ecosystem": "npm"}, "version": "4.17.15"}'
Run in PostTaco
Example response (trimmed)
{
  "vulns": [
    {
      "id": "GHSA-29mw-wpgm-hmr9",
      "summary": "Regular Expression Denial of Service (ReDoS) in lodash",
      "aliases": [
        "CVE-2020-28500"
      ],
      "modified": "2025-09-29T21:12:31.102523Z",
      "published": "2022-01-06T20:30:46Z",
      "database_specific": {
        "severity": "MODERATE",
        "github_reviewed": true,
        "github_reviewed_at": "2021-03-19T22:45:28Z",
        "nvd_published_at": "2021-02-15T11:15:00Z",
        "cwe_ids": [
          "CWE-1333",
          "CWE-400"
        ]
      },
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-28500"
        },
        {
          "type": "WEB",
          "url": "https://github.com/github/advisory-database/pull/6139"
        }
      ],
      "affected": [
        {},
        {}
      ],
      "schema_version": "1.9.0",
      "severity": [
        {
          "type": "CVSS_V3",
          "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
        }
      ]
    },
    {
      "id": "GHSA-35jh-r3h4-6jhm",
      "summary": "Command Injection in lodash",
      "details": "`lodash` versions prior to 4.17.21 are vulnerable to Command Injection via the template function.",
      "aliases": [
        "CVE-2021-23337",
        "CVE-2026-4800"
      ],
      "modified": "2026-09-10T03:49:04.067984836Z",
      "published": "2021-05-06T16:05:51Z",
      "database_specific": {
        "github_reviewed": true,
        "github_reviewed_at": "2021-03-31T23:59:26Z",
        "nvd_published_at": "2021-02-15T13:15:00Z",
        "cwe_ids": [
          "CWE-77",
          "CWE-94"
        ],
        "severity": "HIGH"
      },
      "references": [
        {
          "type": "ADVISORY",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-23337"
        },
        {
          "type": "WEB",
          "url": "https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c"
        }
      ],
      "affected": [
        {},
        {}
      ],
      "schema_version": "1.9.0",
      "severity": [
        {
          "type": "CVSS_V3",
          "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
        }
      ]
    }
  ]
}

Get a vulnerability

curl https://api.osv.dev/v1/vulns/GHSA-jfh8-c2jp-5v3q
Run in PostTaco
Example response (trimmed)
{
  "id": "GHSA-jfh8-c2jp-5v3q",
  "summary": "Remote code injection in Log4j",
  "aliases": [
    "CVE-2021-44228"
  ],
  "modified": "2025-10-22T19:37:02.616807Z",
  "published": "2021-12-10T00:40:56Z",
  "database_specific": {
    "nvd_published_at": "2021-12-10T10:15:00Z",
    "cwe_ids": [
      "CWE-20",
      "CWE-400"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2021-12-10T00:40:41Z"
  },
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-44228"
    },
    {
      "type": "WEB",
      "url": "https://github.com/apache/logging-log4j2/pull/608"
    }
  ],
  "affected": [
    {
      "package": {
        "name": "org.apache.logging.log4j:log4j-core",
        "ecosystem": "Maven",
        "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "2.13.0",
        "2.13.1"
      ],
      "database_specific": {
        "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-jfh8-c2jp-5v3q/GHSA-jfh8-c2jp-5v3q.json"
      }
    },
    {
      "package": {
        "name": "org.apache.logging.log4j:log4j-core",
        "ecosystem": "Maven",
        "purl": "pkg:maven/org.apache.logging.log4j/log4j-core"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "2.0",
        "2.0-beta9"
      ],
      "database_specific": {
        "source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/12/GHSA-jfh8-c2jp-5v3q/GHSA-jfh8-c2jp-5v3q.json"
      }
    }
  ],
  "schema_version": "1.9.0",
  "severity": [
    {
      "type": "CVSS_V3",
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:H"
    }
  ]
}