Skip to content
Roster

Roster Data · Feed

Rust (crates.io) security advisories & malicious packages feed (OSV)

Rolling 30-day feed of new and updated Rust (crates.io) security advisories and malicious-package reports from OSV.dev: package names, affected and fixed versions, severity, CVE aliases. Poll it from CI or a dependency bot instead of crawling GitHub/OSV yourself. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.

What you get

The latest items as JSON. Filter with since, q, or limit. Includes attribution.

Recent items · filter by date or text

Price
0.01 USDC
Freshness
Updated 4 h ago
Refresh
every 3 hours
Rows
155 · 72 KB

Source & license

Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.

Sample

idkindpackagessummaryseveritycvss_vectoraliasesintroduced
GHSA-2cv4-cqwr-gwf7vulnerabilityuvuv: Path traversal on Windows through wheel ext…MODERATECVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:…CVE-2026-1048430.12.7
GHSA-2mjx-qc3c-rqvcvulnerabilityrustlsRustls: TLS 1.3 handshake messages incorrectly …MODERATECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NRUSTSEC-2026-02850.23.13
GHSA-6w6g-hm98-mhgmvulnerabilityhickory-resolverhickory-resolver: Unbounded TC-retry loop in `N…HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:…—0.26.0-beta.1
GHSA-6f2x-v7q7-m7m5vulnerabilityhickory-resolverhickory-resolver follows irrelevant CNAME recor…MODERATECVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:…—0.25.0
GHSA-5j98-2g5x-46v6vulnerabilityhickory-resolverhickory-resolver: Resolver::lookup() and Resolv…HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NCVE-2026-936570

Schema

idstringOSV id (GHSA-…, PYSEC-…, MAL-…).
kindstringvulnerability or malicious-package.
packagesstringAffected package names, semicolon-separated.
summarystringShort summary.
severitystringDatabase severity (LOW…CRITICAL) when given.
cvss_vectorstringCVSS vector when given.
aliasesstringCVE and other aliases.
introducedstringIntroduced versions.
fixedstringFixed versions.
published_atdatetimePublished.
modified_atdatetimeLast modified.
withdrawnbooleanAdvisory withdrawn.
urlstringosv.dev page.

Buy from code

curl -X POST https://roster.network/roster-api/v1/need/buy \
  -H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
  -d '{"listingId":"cap_74791671c240db95","input":{}}'

// SDK
const { matches } = await roster.need("Rust (crates.io) security advisories & malicious packages fe");
const bought = await roster.buy({ listingId: "cap_74791671c240db95" });