Open Source Vulnerability Scraper (OSV.dev)
Pricing
$1.00 / 1,000 records
Open Source Vulnerability Scraper (OSV.dev)
Look up open-source security vulnerabilities from OSV.dev for any package across npm, PyPI, Go, Maven, crates and more. Returns CVE IDs, severity, summary and references. No API key. Pay per vulnerability; empty runs free.
Pricing
$1.00 / 1,000 records
Rating
0.0
(0)
Developer
Christian Pichichero
Maintained by CommunityActor stats
0
Bookmarked
2
Total users
1
Monthly active users
7 days ago
Last modified
Categories
Share
Open Source Vulnerability Scraper (OSV.dev) — a fast, reliable vulnerability scraper that needs no API key. You pay only for the results you get: failed or empty runs are always free.
This vulnerability scraper runs on the Apify platform, so you can call it from the API, run it on a schedule, or export results to JSON, CSV, Excel, or Google Sheets.
What this scraper does
- Extracts structured vulnerability data with no browser or API key required
- Returns clean JSON, one record per result — ready for sheets, databases, or apps
- Pay-per-result pricing: you are never charged for a run that returns nothing
- Runs on demand or on a schedule, and integrates with 5,000+ apps via the Apify API and webhooks
What data you get
Each result record includes fields such as:
- Id (
id) — e.g."GHSA-29mw-wpgm-hmr9" - Summary (
summary) — e.g."Regular Expression Denial of Service (ReDoS) in lodash" - Details (
details) — e.g."All versions of package lodash prior to 4.17.21 are vuln... - Aliases (
aliases) — e.g.["CVE-2020-28500"] - Cve Ids (
cveIds) — e.g.["CVE-2020-28500"] - Package Name (
packageName) — e.g."lodash" - Ecosystem (
ecosystem) — e.g."npm" - Severity (
severity) — e.g."CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" - Severity Rating (
severityRating) — e.g."MODERATE" - Cvss Vector (
cvssVector) — e.g."CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L" - Cwe Ids (
cweIds) — e.g.["CWE-1333", "CWE-400"] - Published (
published) — e.g."2022-01-06T20:30:46Z" - Modified (
modified) — e.g."2025-09-29T21:12:31.102523Z" - Affected Packages (
affectedPackages) — e.g.["lodash", "lodash-es", "lodash.trimend", "lodash.trim", ... - References (
references) — e.g.["https://nvd.nist.gov/vuln/detail/CVE-2020-28500", "http...
Input
| Field | Type | Description |
|---|---|---|
packages | array | Package names to look up vulnerabilities for (one query per name), e.g. lodash, express. Names must match t... |
ecosystem | string | Package ecosystem the names belong to. Applied to every package in this run. |
version | string | Optional exact package version. When set, results are narrowed to vulnerabilities affecting that specific v... |
maxResults | integer | Maximum number of vulnerability records to return per package. |
Example output
{"type": "vulnerability","id": "GHSA-29mw-wpgm-hmr9","summary": "Regular Expression Denial of Service (ReDoS) in lodash","details": "All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.","aliases": ["CVE-2020-28500"],"cveIds": ["CVE-2020-28500"],"packageName": "lodash","ecosystem": "npm","severity": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","severityRating": "MODERATE","cvssVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cweIds": ["CWE-1333","CWE-400"],"published": "2022-01-06T20:30:46Z","modified": "2025-09-29T21:12:31.102523Z","affectedPackages": ["lodash","lodash-es","lodash.trimend","lodash.trim","lodash-rails"],"references": ["https://nvd.nist.gov/vuln/detail/CVE-2020-28500","https://github.com/lodash/lodash"],"url": "https://osv.dev/vulnerability/GHSA-29mw-wpgm-hmr9","query": "lodash (npm)","scrapedAt": "2026-07-11T00:00:00Z"}
Use cases
- Monitor packages, repos, and dependencies
- Automate security and license audits
- Build developer dashboards and alerts
- Enrich internal tools and integrations
Run it as a monitor (alerts on new vulnerability)
Schedule this vulnerability scraper to run automatically — hourly, daily, or on any cron schedule — with the built-in Apify Scheduler, and have results pushed to you by webhook, email, Slack, or your own app the moment they're ready. It's the easiest way to monitor vulnerability for changes over time and get alerted the instant something new appears — no manual runs. Because pricing is per result, a scheduled monitor only ever charges you for the data each run actually returns.
Pricing
This actor uses pay-per-result pricing at $0.0006 per record. There is no monthly fee and no start fee — and empty or failed runs cost $0, so you only ever pay for data you actually receive.
Frequently asked questions
Do I need an API key or account for the source? No. This vulnerability scraper works out of the box with no API key required.
What happens if a run returns no results? You are not charged. Billing is per result, so empty or failed runs are free.
Can I run the vulnerability scraper on a schedule? Yes. Use the Apify Scheduler to run it hourly, daily, or on any cron schedule, and get results by webhook or API.
What export formats are supported? Results can be exported as JSON, CSV, Excel, HTML, or pushed to Google Sheets, a database, or your own app via the Apify API.
Is the data structured? Yes. Every vulnerability result is a clean, flat JSON record you can use immediately.