Roster Data · Feed
Rust (crates.io) security advisories & malicious packages feed (OSV)
Rolling 30-day feed of new and updated Rust (crates.io) security advisories and malicious-package reports from OSV.dev: package names, affected and fixed versions, severity, CVE aliases. Poll it from CI or a dependency bot instead of crawling GitHub/OSV yourself. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.
What you get
The latest items as JSON. Filter with since, q, or limit. Includes attribution.
Recent items · filter by date or text
- Price
- 0.01 USDC
- Freshness
- Updated 4 h ago
- Refresh
- every 3 hours
- Rows
- 155 · 72 KB
Source & license
- OSV — Open Source Vulnerabilities · CC-BY-4.0
Source: OSV.dev (CC BY 4.0); individual advisories carry their upstream database attribution.
Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.
Sample
| id | kind | packages | summary | severity | cvss_vector | aliases | introduced |
|---|---|---|---|---|---|---|---|
| GHSA-2cv4-cqwr-gwf7 | vulnerability | uv | uv: Path traversal on Windows through wheel ext… | MODERATE | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:… | CVE-2026-104843 | 0.12.7 |
| GHSA-2mjx-qc3c-rqvc | vulnerability | rustls | Rustls: TLS 1.3 handshake messages incorrectly … | MODERATE | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | RUSTSEC-2026-0285 | 0.23.13 |
| GHSA-6w6g-hm98-mhgm | vulnerability | hickory-resolver | hickory-resolver: Unbounded TC-retry loop in `N… | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:… | — | 0.26.0-beta.1 |
| GHSA-6f2x-v7q7-m7m5 | vulnerability | hickory-resolver | hickory-resolver follows irrelevant CNAME recor… | MODERATE | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:… | — | 0.25.0 |
| GHSA-5j98-2g5x-46v6 | vulnerability | hickory-resolver | hickory-resolver: Resolver::lookup() and Resolv… | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N | CVE-2026-93657 | 0 |
Schema
| id | string | OSV id (GHSA-…, PYSEC-…, MAL-…). |
| kind | string | vulnerability or malicious-package. |
| packages | string | Affected package names, semicolon-separated. |
| summary | string | Short summary. |
| severity | string | Database severity (LOW…CRITICAL) when given. |
| cvss_vector | string | CVSS vector when given. |
| aliases | string | CVE and other aliases. |
| introduced | string | Introduced versions. |
| fixed | string | Fixed versions. |
| published_at | datetime | Published. |
| modified_at | datetime | Last modified. |
| withdrawn | boolean | Advisory withdrawn. |
| url | string | osv.dev page. |
Buy from code
curl -X POST https://roster.network/roster-api/v1/need/buy \
-H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
-d '{"listingId":"cap_74791671c240db95","input":{}}'
// SDK
const { matches } = await roster.need("Rust (crates.io) security advisories & malicious packages fe");
const bought = await roster.buy({ listingId: "cap_74791671c240db95" });