{"uid":"cap_XAOWoGEaIAiz254hN96iv","slug":"apex-package-vulnerability-kev-checker-0bd6b531","name":"APEX Package Vulnerability + KEV Checker","description":"Known vulnerabilities for one package version from OSV.dev, with CISA exploited-in-the-wild flag and the fixed version. Should I install this? Pass ?package=lodash&ecosystem=npm&version=4.17.15 (npm, PyPI, Go, crates.io, Maven, NuGet, RubyGems, Packagist, Hex, Pub) and get every known advisory for that exact version from OSV.dev (GitHub, PyPA, Go and RustSec databases), whether any of them is on CISA's Known Exploited Vulnerabilities list, severity, and the version that fixes each.","url":"https://apexfaucet.xyz/api/x402/software-risk?utm_source=zero.xyz","method":"GET","headers":{},"bodySchema":{"type":"object","$schema":"https://json-schema.org/draft/2020-12/schema","required":["input"],"properties":{"input":{"type":"object","required":["type","method","queryParams"],"properties":{"type":{"type":"string","const":"http"},"method":{"enum":["GET"],"type":"string"},"queryParams":{"type":"object","required":["package","ecosystem","version"],"properties":{"package":{"type":"string","maxLength":214,"minLength":1,"description":"Package name exactly as the registry has it (Maven: group:artifact)."},"version":{"type":"string","maxLength":64,"minLength":1,"description":"The exact version to check."},"ecosystem":{"enum":["npm","PyPI","Go","crates.io","Maven","NuGet","RubyGems","Packagist","Hex","Pub"],"type":"string","description":"Package ecosystem."}}}}},"output":{"type":"object"}}},"responseSchema":null,"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.003","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.003/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.003","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_6yyevdupUTfOb2Ak4Bg5_","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.003","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Returns all known CVE/OSV advisories for a specific package version, CISA Known Exploited Vulnerabilities (KEV) flag, severity scores, and the version that fixes each issue.","exampleAgentPrompt":"Is lodash version 4.17.15 from npm safe to use? Check if it has any known CVEs, whether any are actively exploited in the wild according to CISA's KEV list, and what version I should upgrade to.","exampleUseCases":[{"title":"Pre-install npm dependency check","prompt":"Before I add axios 1.3.4 from npm to my project, can you check if it has any known vulnerabilities and whether any are being actively exploited in the wild?"},{"title":"Python package audit for CI pipeline","prompt":"We're using requests 2.27.0 from PyPI — does it have any CVEs, is it on CISA's exploited vulnerabilities list, and what version should we upgrade to?"},{"title":"Java Maven library security review","prompt":"I need to know if log4j-core version 2.14.1 from Maven has known security advisories and whether any are flagged as exploited in the wild by CISA — and tell me the fixed version if so."}],"resultDescription":"A structured response listing every known OSV advisory for the specified package version, including CVE IDs, severity ratings, whether each advisory appears on CISA's Known Exploited Vulnerabilities (KEV) catalog, and the minimum version that resolves each vulnerability.","failureModes":["Unknown package name or version returns empty advisory list","Unsupported ecosystem returns validation error","OSV.dev upstream unavailability causes timeout or error","Very new CVEs not yet indexed in OSV.dev may be missing","Package name format errors for Maven (requires group:artifact) cause lookup failure"],"whenToPreferThis":"Choose this endpoint when you need a quick, per-version vulnerability assessment that combines OSV.dev's multi-database advisory coverage with CISA's KEV active-exploitation flag in a single call — especially useful before installing or upgrading a dependency, or for automated CI/CD security gates. It covers 10 major ecosystems and surfaces the exact fix version, saving manual cross-referencing of NVD, OSV, and CISA separately.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-10-01T06:42:41.977Z","isFirstParty":false,"canonicalSlug":"apex-package-vulnerability-kev-checker-0bd6b531"}