Roster Data · Feed
Maven security advisories & malicious packages feed (OSV)
Rolling 30-day feed of new and updated Maven security advisories and malicious-package reports from OSV.dev: package names, affected and fixed versions, severity, CVE aliases. Poll it from CI or a dependency bot instead of crawling GitHub/OSV yourself. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.
What you get
The latest items as JSON. Filter with since, q, or limit. Includes attribution.
Recent items · filter by date or text
- Price
- 0.01 USDC
- Freshness
- Updated 3 h ago
- Refresh
- every 3 hours
- Rows
- 158 · 85 KB
Source & license
- OSV — Open Source Vulnerabilities · CC-BY-4.0
Source: OSV.dev (CC BY 4.0); individual advisories carry their upstream database attribution.
Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.
Sample
| id | kind | packages | summary | severity | cvss_vector | aliases | introduced |
|---|---|---|---|---|---|---|---|
| GHSA-wmxr-6j5f-838p | vulnerability | org.keycloak:keycloak-saml-adapter-core;org.key… | Duplicate Advisory: Keycloak: Unauthorized acce… | HIGH | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L | — | 0;26.3.0;26.5.0 |
| GHSA-xv6h-r36f-3gp5 | vulnerability | org.keycloak:keycloak-saml-adapter-core;org.key… | Keycloak: Denial of Service due to excessive SA… | MODERATE | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L | BIT-keycloak-2026-2575;CVE-2026-2575 | 0 |
| GHSA-2p5w-cvg5-gc5c | vulnerability | org.hibernate:hibernate-core | Hibernate vulnerable to SQL Injection | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L | CVE-2026-0603 | 5.2.8 |
| GHSA-95h4-w6j8-2rp8 | vulnerability | io.undertow:undertow-core | Undertow MadeYouReset HTTP/2 DDoS Vulnerability | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | CVE-2025-9784 | 0;2.3.0.Alpha1 |
| GHSA-pc63-qcmh-9cmg | vulnerability | org.springframework:spring-webmvc | Spring Framework Improper Path Limitation in Xs… | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | CVE-2026-47884 | 0;5.3.0;6.0.0;6.1.0;6.2.0;7.0.0 |
Schema
| id | string | OSV id (GHSA-…, PYSEC-…, MAL-…). |
| kind | string | vulnerability or malicious-package. |
| packages | string | Affected package names, semicolon-separated. |
| summary | string | Short summary. |
| severity | string | Database severity (LOW…CRITICAL) when given. |
| cvss_vector | string | CVSS vector when given. |
| aliases | string | CVE and other aliases. |
| introduced | string | Introduced versions. |
| fixed | string | Fixed versions. |
| published_at | datetime | Published. |
| modified_at | datetime | Last modified. |
| withdrawn | boolean | Advisory withdrawn. |
| url | string | osv.dev page. |
Buy from code
curl -X POST https://roster.network/roster-api/v1/need/buy \
-H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
-d '{"listingId":"cap_3c6e4e266e84683d","input":{}}'
// SDK
const { matches } = await roster.need("Maven security advisories & malicious packages feed (OSV)");
const bought = await roster.buy({ listingId: "cap_3c6e4e266e84683d" });