OSV.dev API
APIQuery known vulnerabilities by open-source package version or commit
- Price
- Free public API
- Access
- No API key needed
About
OSV.dev aggregates open-source vulnerability data and provides a public API to look up known issues affecting a package version or commit. Query packages one at a time or in batches; results help power dependency checks but do not inspect source code.
What you can do with it
- Check a dependency version for known vulnerabilities
- Batch-query versions from a dependency inventory
- Fetch a full vulnerability record by OSV identifier
Get started
- Identify a dependency's package name, ecosystem and version
- POST the package coordinates to the OSV query endpoint
- Inspect returned vulnerability IDs and fetch records if needed
Example
curl -X POST https://api.osv.dev/v1/query \
-H "Content-Type: application/json" \
-d '{"version":"2.4.1","package":{"name":"jinja2","ecosystem":"PyPI"}}'Details
- Hosting
- Hosted service
- Available in
- Worldwide
- MCP server
- None