Vulnerability Check
OSV.dev · Security · 1 endpoint
Is this package affected? OSV.dev's advisories for any npm, PyPI, Go, Maven, or crates.io package, optionally pinned to a version.
Base URL
Endpoint
Snippet
Request — cURL
v1
curl https://api.diraz.ae/v1/security/osv \
-H "Authorization: Bearer drz_live_…"Query parameters
- ecosystemstring · required
- `npm`, `PyPI`, `Go`, `Maven`, `crates.io`, `Packagist`, `RubyGems`, or `NuGet`.
- packagestring · required
- The package name.
- versionstring · optional
- Pin to a version to get only the advisories that actually affect it.
- max_ageinteger (seconds) · optional
- Ask for data no older than this. Clamped to the product's own floor, so it can narrow the window but never force a refresh on every call.Default: 300
Example response
200 OK
v1
{
"data": {
"package": "lodash",
"ecosystem": "npm",
"version": null,
"vulnerabilities": [
{
"id": "GHSA-29mw-wpgm-hmr9",
"summary": "Regular Expression Denial of Service in lodash",
"aliases": ["CVE-2020-8203"],
"url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9"
}
]
},
"meta": {
"request_id": "req_7Q2fK4mZ",
"as_of": "2026-08-21T14:05:00.000Z",
"age_seconds": 42,
"next_update_at": "2026-08-21T15:05:00.000Z"
}
}- vulnerabilities[].id / aliases[]
- The advisory's GHSA or CVE id, and every other identifier it travels under.
- vulnerabilities[].summary / url
- What it does, and where the full advisory lives.
Errors
401 Unauthorized
v1
{
"error": {
"code": "UNAUTHORIZED",
"message": "The API key is invalid, expired, or revoked."
},
"meta": {
"request_id": "req_7Q2fK4mZ"
}
}Every failure carries a stable machine-readable code before the human message, and the same meta.request_id the successful responses carry. Quote it and we can find your exact request.
Errors are free
Nothing on this page is billed. You are charged for a 2xx and nothing else — a rejected key, a bad parameter, a rate limit, or an outage on our side all cost you zero. Retry without watching the meter.
- UNAUTHORIZEDHTTP 401
- Missing, malformed, expired, or revoked API key.
- FORBIDDENHTTP 403
- The key is valid but lacks the scope this product needs.
- VALIDATION_ERRORHTTP 422
- A query parameter is the wrong type or out of range.
- RATE_LIMITEDHTTP 429
- Rate limit exhausted. `Retry-After` says how long to wait.
- SERVICE_UNAVAILABLEHTTP 503
- No data recent enough to serve. Carries `Retry-After`, and is never billed.
- Status
- Operational
- Category
- Security
- Scope
- market:read
- Rate limit
- 120 requests / 60s per key
- Pricing
- 1 credit / request
- Vulnerability Check
1/1 passing
Every response is timestamped. as_of is when the data was published, age_seconds how old that is now, and next_update_at when newer data is expected.
Three shapes to handle:
- Up to date200
The data is inside its published window. The overwhelming majority of requests.
- Delayeddelayed: true
Newer data is late. You still get the most recent there is, flagged so you can decide whether to use it.
- Unavailable503
Nothing recent enough to serve. Carries Retry-After, and is never billed.