cve_lookup
Look up NVD CVE records by ID, keyword, CPE, severity, or date range, and get each vulnerability's CISA KEV status.
Instructions
Look up NIST NVD CVE records (keyless; services.nvd.nist.gov CVE API 2.0) — exact by cveId OR search by keyword/cpeName/cvssV3Severity/date range — each row JOINED with its CISA KEV status. Returns { results:[{ cveId, vulnStatus, rejected, published, lastModified, description, cvssMetrics:[{version,source,type,baseScore,baseSeverity,vectorString,exploitabilityScore,impactScore}], primaryCvss:{version,baseScore,baseSeverity,type}|null, cwes, references, kev }] } + honest _meta. Optional kevOnly, resultsPerPage (≤2000, def 50), startIndex. CVSS HONESTY: every ^cvssMetric key (V2/V30/V31/V40) is its own element — versions never conflated; V2 baseSeverity reads from metric level; primaryCvss is highest-version, type:Primary preferred but FALLS BACK to highest Secondary (real CNA score never dropped), null ONLY when no CVSS exists — base scores null-never-0. KEV HONESTY: kev is {listed:true,dateAdded,dueDate,ransomware,requiredAction,catalogVersion} | {listed:false,note} | {listed:null,status:'unavailable'}; not-listed ≠ safe (absence is NOT a clearance); if KEV catalog cannot load, kev.listed degrades to NULL (never false) with fieldsUnavailable:['kev']; a kevOnly filter during KEV outage THROWS. PAGINATION from NVD EXACT totalResults (never page length). Genuine totalResults:0 → honest found:false; 403/429 → rate_limited THROWS with NVD_API_KEY tier disclosure; 404/5xx/timeout/off-host THROW. Optional free NVD_API_KEY (env) lifts the rate — sent ONLY in the apiKey header.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| cveId | No | Exact CVE identifier CVE-YYYY-NNNN (^CVE-\d{4}-\d+$, validated client-side). Exact-lookup mode; a malformed cveId is rejected (invalid_input) — a malformed cveId 404s upstream. At least one of cveId/keyword/cpeName/cvssV3Severity/a date range is REQUIRED. | |
| cpeName | No | A CPE 2.3 formatted string to match affected products (cpe:2.3:[aho]:… — e.g. cpe:2.3:a:apache:log4j:2.14.1:*:*:*:*:*:*:*). Non-CPE input is rejected (invalid_input). | |
| kevOnly | No | When true, return ONLY rows listed in the CISA KEV catalog. ★If the KEV catalog cannot be loaded, this THROWS (a KEV-membership filter is unanswerable without a loaded catalog) — it NEVER returns a silently-empty set (which would falsely read as 'none on the mandatory-remediation list'). | |
| keyword | No | Free-text keyword search (NVD keywordSearch) over CVE descriptions (e.g. 'log4j', 'apache struts'). Control chars stripped, length-capped; rides only as a query param (SSRF-safe). | |
| pubEndDate | No | Publication-date window END (ISO YYYY-MM-DD). Paired with pubStartDate. | |
| startIndex | No | Zero-based page offset (default 0). Pagination derives from NVD's exact totalResults, never the page length. | |
| pubStartDate | No | Publication-date window START (ISO YYYY-MM-DD). PAIRED with pubEndDate (both required together — NVD 404s a lone bound). A span >120 days is clamped forward to 120 days BEFORE the request and disclosed. | |
| cvssV3Severity | No | Filter to a CVSS v3 base severity band (LOW|MEDIUM|HIGH|CRITICAL). | |
| lastModEndDate | No | Last-modified window END (ISO YYYY-MM-DD). Paired with lastModStartDate. | |
| resultsPerPage | No | Rows per page (default 50, max 2000 — NVD's cap). Over-cap is refused, never silently clamped. | |
| lastModStartDate | No | Last-modified window START (ISO YYYY-MM-DD). PAIRED with lastModEndDate (both required together). A span >120 days is clamped + disclosed. |