Skip to content
Roster

Roster Data · Feed

Maven security advisories & malicious packages feed (OSV)

Rolling 30-day feed of new and updated Maven security advisories and malicious-package reports from OSV.dev: package names, affected and fixed versions, severity, CVE aliases. Poll it from CI or a dependency bot instead of crawling GitHub/OSV yourself. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.

What you get

The latest items as JSON. Filter with since, q, or limit. Includes attribution.

Recent items · filter by date or text

Price
0.01 USDC
Freshness
Updated 3 h ago
Refresh
every 3 hours
Rows
158 · 85 KB

Source & license

Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.

Sample

idkindpackagessummaryseveritycvss_vectoraliasesintroduced
GHSA-wmxr-6j5f-838pvulnerabilityorg.keycloak:keycloak-saml-adapter-core;org.key…Duplicate Advisory: Keycloak: Unauthorized acce…HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:L—0;26.3.0;26.5.0
GHSA-xv6h-r36f-3gp5vulnerabilityorg.keycloak:keycloak-saml-adapter-core;org.key…Keycloak: Denial of Service due to excessive SA…MODERATECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LBIT-keycloak-2026-2575;CVE-2026-25750
GHSA-2p5w-cvg5-gc5cvulnerabilityorg.hibernate:hibernate-coreHibernate vulnerable to SQL InjectionHIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:LCVE-2026-06035.2.8
GHSA-95h4-w6j8-2rp8vulnerabilityio.undertow:undertow-coreUndertow MadeYouReset HTTP/2 DDoS VulnerabilityHIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCVE-2025-97840;2.3.0.Alpha1
GHSA-pc63-qcmh-9cmgvulnerabilityorg.springframework:spring-webmvcSpring Framework Improper Path Limitation in Xs…CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE-2026-478840;5.3.0;6.0.0;6.1.0;6.2.0;7.0.0

Schema

idstringOSV id (GHSA-…, PYSEC-…, MAL-…).
kindstringvulnerability or malicious-package.
packagesstringAffected package names, semicolon-separated.
summarystringShort summary.
severitystringDatabase severity (LOW…CRITICAL) when given.
cvss_vectorstringCVSS vector when given.
aliasesstringCVE and other aliases.
introducedstringIntroduced versions.
fixedstringFixed versions.
published_atdatetimePublished.
modified_atdatetimeLast modified.
withdrawnbooleanAdvisory withdrawn.
urlstringosv.dev page.

Buy from code

curl -X POST https://roster.network/roster-api/v1/need/buy \
  -H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
  -d '{"listingId":"cap_3c6e4e266e84683d","input":{}}'

// SDK
const { matches } = await roster.need("Maven security advisories & malicious packages feed (OSV)");
const bought = await roster.buy({ listingId: "cap_3c6e4e266e84683d" });