Public CVE Feed
A public, unauthenticated feed of every Linux kernel CVE we track — in OSV 1.6 and CycloneDX VDR formats. Plug it into Trivy, Grype, Renovate, or your own pipeline alongside your existing sources. Same CVE IDs as NVD, just earlier.
NVD lag killer for kernel CVEs.
kernel.org publishes new CVEs to cvelistV5 within hours
of disclosure; NVD enrichment commonly trails by 1–4 weeks and
sometimes never catches up. We pull cvelistV5 directly
and re-publish it in scanner-native formats so your tooling sees
kernel CVEs the same day they land — not the same month.
Quick start
The manifest at /feed/index.json is fully public. Every
other endpoint needs a free KernelScan account:
register, generate a personal access
token from the Account page, and send it as a
Bearer header.
# Manifest — public, no auth needed
curl https://kernelscan.io/feed/index.json
# Set your token once
export KS_TOKEN=ks_live_…
# OSV — every kernel CVE in one array
curl -H "Authorization: Bearer $KS_TOKEN" https://kernelscan.io/feed/osv/all.json
# CycloneDX VDR — every kernel CVE in one BOM
curl -H "Authorization: Bearer $KS_TOKEN" https://kernelscan.io/feed/cyclonedx/all.json
# A single CVE
curl -H "Authorization: Bearer $KS_TOKEN" https://kernelscan.io/feed/osv/CVE-2024-12345.json
curl -H "Authorization: Bearer $KS_TOKEN" https://kernelscan.io/feed/cyclonedx/CVE-2024-12345.json
Endpoints
Manifest
Top-level metadata: total CVE count, last-modified timestamp, license, and the URLs of every other endpoint. Cheap to poll.
OSV — bulk
JSON array of OSV 1.6 records — one per kernel CVE we track. The drop-in input for OSV-Scanner, Trivy's OSV mode, and other OSV-aware scanners.
OSV — per CVE
One OSV 1.6 record. Use when you only need a single CVE — handy for webhooks and CI fingerprinting.
CycloneDX VDR — bulk
A single CycloneDX 1.6 Vulnerability Disclosure Report containing every kernel CVE. Native to Dependency-Track; richer property layout than OSV for our AI-extended fields.
CycloneDX VDR — per CVE
A single-vulnerability VDR. Same shape as the bulk endpoint, scoped to one CVE.
Freshness
Our pipeline polls cvelistV5 hourly and the NVD API on a
rolling cadence. New CVEs land in this feed within ~4 hours of CNA
publication; AI-generated CVSS / CWE follows once auditing completes
(typically minutes after that).
Every response carries a Last-Modified header and
X-KernelScan-Feed-* headers describing tier and license.
/feed/index.json exposes the same timestamp as a JSON
field for clients that prefer in-band metadata.
What's in the feed by tier
The same URL serves all logged-in users. Free accounts get a moving 60-day window of recently-published kernel CVEs plus AI-calculated CVSS / severity / vector / CWE — enough to keep Dependency-Track and friends current on new disclosures. Basic+ plans (Basic, Pro, Enterprise) additionally unlock the full historical corpus, the AI-generated risk summary, and the vulnerability analysis.
| Field | Free account | Basic+ account |
|---|---|---|
| Coverage window | Last 60 days | All tracked CVEs |
| CVE ID, description, references, fix versions | Yes | Yes |
| NVD CVSS / CWE (when available) | Yes | Yes |
| AI-calculated CVSS, severity, vector, CWE | Yes | Yes |
| Affected component, classification, CISA KEV flag | Yes | Yes |
| AI risk summary | — | Yes |
| AI vulnerability analysis | — | Yes |
| CONFIG_* dependency mapping, factor verdicts | Paid product | Paid product |
Config-gated applicability ("does my kernel build need this patch?") is the core of our paid product and stays out of the feed. The feed makes a CVE more actionable in isolation; the paid product makes it actionable for your specific kernel.
Using with Dependency-Track
For Dependency-Track, use the open-source
KernelScan analyzer plugin — not this OSV feed. The
plugin runs in-process in your DT apiserver, matches the kernel
component in each project's SBOM, and reports only the CVEs
reachable in that kernel's .config, under
native CVE-* / NVD identity so findings merge
with DT's own NVD records — no duplicates. A companion VEX push then
marks the config-gated CVEs Not Affected with the exact
CONFIG_* justification.
6.6.69 host pulled ~8,550 "applicable" CVEs from a flat OSV
feed versus the ~3,780 that actually apply to the 6.6 line. The plugin's
config-aware, per-branch analysis removes both the cross-branch noise
and the config-unreachable CVEs by construction.
Source, install steps, and the downloadable JAR: github.com/kernelscan/kernelscan-dt-plugin · latest release. The full setup walkthrough is in the Docs.
This OSV / CycloneDX feed remains the right choice for generic OSV-aware scanners — Trivy, Grype, OSV-Scanner, Renovate — that consume the records directly.
License & attribution
Feed contents are provided under Creative Commons Attribution 4.0 International (CC-BY-4.0). You may freely redistribute, mirror, and integrate this feed into commercial or open-source products, including SBOM and vulnerability scanning pipelines.
Attribution requirement: a visible note crediting KernelScan
(https://kernelscan.io) wherever the data is surfaced to
end users — typically in your tool's vulnerability source list or a
comparable "data sources" page. Each record carries the attribution
string in database_specific.kernelscan.attribution
(OSV) or kernelscan.io:attribution (CycloneDX) so it
flows through automatically.
What you get out of the box
- Records keyed by
KSCAN-CVE-YYYY-NNNNNwith the CVE id inaliases— OSV consumers collapse to one finding, both sources attributed - Per-LTS-branch fix versions (mainline, 6.6, 6.1, 5.15, …) as separate ranges
- NVD CVSS / CWE when present, AI-generated CVSS / CWE always
- Direct kernel.org and patch URLs as
FIXreferences - CISA KEV exposure flag per CVE
- Engine version stamped on every record for provenance
Questions or integration help with the feed? Email hello@kernelscan.io. For the Dependency-Track plugin, open an issue on GitHub.