OSV.dev API

API

Query known vulnerabilities by open-source package version or commit

Price
Free public API
Access
No API key needed

About

OSV.dev aggregates open-source vulnerability data and provides a public API to look up known issues affecting a package version or commit. Query packages one at a time or in batches; results help power dependency checks but do not inspect source code.

What you can do with it

  • Check a dependency version for known vulnerabilities
  • Batch-query versions from a dependency inventory
  • Fetch a full vulnerability record by OSV identifier

Get started

  1. Identify a dependency's package name, ecosystem and version
  2. POST the package coordinates to the OSV query endpoint
  3. Inspect returned vulnerability IDs and fetch records if needed

Example

curl -X POST https://api.osv.dev/v1/query \
  -H "Content-Type: application/json" \
  -d '{"version":"2.4.1","package":{"name":"jinja2","ecosystem":"PyPI"}}'

Details

Hosting
Hosted service
Available in
Worldwide
MCP server
None

Tasks

Alternatives

Other tools for the same tasks.

Last checked on .