{"providers":[{"id":"nvd","host":"services.nvd.nist.gov","optional_key":"NVD_API_KEY","cache_ttl_seconds":21600,"rate_limit":"Keyless ~5 requests / 30s per IP; with a free NVD_API_KEY ~50 / 30s. One CVE per request (no multi-cveId) — cached aggressively.","license":"NVD (NIST National Vulnerability Database) — US Government public domain.","attribution":"This product uses the NVD API but is not endorsed or certified by the NVD. Data: NIST National Vulnerability Database (nvd.nist.gov)."},{"id":"cisa_kev","host":"www.cisa.gov","optional_key":null,"cache_ttl_seconds":21600,"rate_limit":"Whole catalog as one JSON (~1.5 MB); loaded once into memory, refreshed on TTL.","license":"CISA Known Exploited Vulnerabilities catalog — US Government public domain.","attribution":"CISA Known Exploited Vulnerabilities (KEV) catalog (cisa.gov) — public domain"},{"id":"osv","host":"api.osv.dev","optional_key":null,"cache_ttl_seconds":21600,"rate_limit":"No documented rate-limit; batch via POST /v1/querybatch.","license":"OSV.dev aggregated advisory data (Google); GHSA records under CC-BY-4.0 — commercial use OK with attribution.","attribution":"OSV.dev (osv.dev) — aggregated open-source vulnerability database; includes GitHub Security Advisories (CC-BY-4.0)"},{"id":"epss","host":"api.first.org","optional_key":null,"cache_ttl_seconds":21600,"rate_limit":"Keyless; comma-separated batch of many CVEs in ONE call.","license":"EPSS (Exploit Prediction Scoring System) — free, FIRST.org.","attribution":"EPSS by FIRST.org (first.org/epss) — Exploit Prediction Scoring System"}],"supported_ecosystems":["npm","PyPI","Maven","crates.io","Go","Packagist","RubyGems","NuGet"],"nvd_api_key_configured":false,"kev_catalog_version":null,"note":"Provenance, licensing and rate-limits of the public vulnerability registries the paid /cve/* routes fuse (NVD, CISA KEV, OSV.dev, EPSS). All sources are keyless (an optional NVD key only raises the rate limit); live queries only. Value-add is the cross-registry FUSION + deterministic patch-priority score, not a resale.","disclaimer":"Automated vulnerability risk INDICATORS fused from public vulnerability registries (NVD, CISA KEV, OSV.dev, EPSS), NOT security advice and NOT a guarantee. Scores are for prioritization only; absence of a record is not proof of safety. Always verify against the authoritative source and vendor advisories before acting."}