Roster Data · Feed
npm security advisories & malicious packages feed (OSV)
Rolling 30-day feed of new and updated npm security advisories and malicious-package reports from OSV.dev: package names, affected and fixed versions, severity, CVE aliases. Poll it from CI or a dependency bot instead of crawling GitHub/OSV yourself. Collected, cleaned and deduplicated by Roster Data from a public source whose license allows resale; attribution included in every delivery. You only pay when data is delivered.
What you get
The latest items as JSON. Filter with since, q, or limit. Includes attribution.
Recent items · filter by date or text
- Price
- 0.01 USDC
- Freshness
- Updated 4 h ago
- Refresh
- every 3 hours
- Rows
- 250 · 103 KB
Source & license
- OSV — Open Source Vulnerabilities · CC-BY-4.0
Source: OSV.dev (CC BY 4.0); individual advisories carry their upstream database attribution.
Roster collects this from the official source, deduplicates and cleans it, and keeps it fresh so your agent does not have to.
Sample
| id | kind | packages | summary | severity | cvss_vector | aliases | introduced |
|---|---|---|---|---|---|---|---|
| GHSA-7c34-32v3-j575 | vulnerability | payload | Payload relationship-query authorization bypass | MODERATE | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:… | CVE-2026-105852 | 0;4.0.0-canary.0 |
| GHSA-8r29-2mp2-pmrw | vulnerability | @payloadcms/plugin-ecommerce | Payload Ecommerce has an order confirmation val… | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:… | CVE-2026-105850 | 0;4.0.0-canary.0 |
| GHSA-xgv3-crq2-6f69 | vulnerability | payload | Payload: Token refresh and password reset respo… | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:… | CVE-2026-105853 | 3.0.0;4.0.0-canary.0 |
| GHSA-238x-w2j9-gwwr | vulnerability | payload | Payload vulnerable to API key disclosure throug… | HIGH | CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:… | CVE-2026-105849 | 3.0.0;4.0.0-canary.0 |
| GHSA-2g7p-5934-q4w7 | vulnerability | payload | Payload: ReDoS in Multipart Content-Type Valida… | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:… | CVE-2026-105854 | 3.0.0;4.0.0-canary.0 |
Schema
| id | string | OSV id (GHSA-…, PYSEC-…, MAL-…). |
| kind | string | vulnerability or malicious-package. |
| packages | string | Affected package names, semicolon-separated. |
| summary | string | Short summary. |
| severity | string | Database severity (LOW…CRITICAL) when given. |
| cvss_vector | string | CVSS vector when given. |
| aliases | string | CVE and other aliases. |
| introduced | string | Introduced versions. |
| fixed | string | Fixed versions. |
| published_at | datetime | Published. |
| modified_at | datetime | Last modified. |
| withdrawn | boolean | Advisory withdrawn. |
| url | string | osv.dev page. |
Buy from code
curl -X POST https://roster.network/roster-api/v1/need/buy \
-H "Authorization: Bearer $ROSTER_API_KEY" -H "content-type: application/json" \
-d '{"listingId":"cap_864521f6b017604c","input":{}}'
// SDK
const { matches } = await roster.need("npm security advisories & malicious packages feed (OSV)");
const bought = await roster.buy({ listingId: "cap_864521f6b017604c" });