Skip to content
External endpointresponds

osv-advisory-mcp-server

Query OSV.dev for package vulnerabilities and batch-audit dependency lists via MCP.

Endpoint URL
https://osv-advisory.caseyjhand.com/mcp
Current status
responds
Last checked
Aug 17, 2026, 05:06 AM UTC
Check
MCP initialize · 8s limit
Latency
347 ms
Response record
4 of 4 rounds
Transport
streamable-http
Source
mcp_registry
Registry name
io.github.cyanheads/osv-advisory-mcp-server

Current observation

This endpoint answered at its latest recorded check.

What this server reports about itself

Self-reported at initialize. Not verified by Licium.

Server name
osv-advisory-mcp-server
Version
0.1.12
Capability keys
logging, resources, tools, prompts
Tool names
osv_list_ecosystems, osv_query_package, osv_get_vulnerability, osv_query_batch
Instructions excerpt

This server provides read-only access to the OSV.dev vulnerability database. - Use osv_list_ecosystems to discover valid ecosystem identifier strings before querying. - Use osv_query_package to check if a single package version is vulnerable. - Use osv_query_batch for dependency audits — pass a full lockfile as {name, ecosystem, version} tuples. - Use osv_get_vulnerability for the full advisory record when osv_query_package returns a vuln ID. - OSV results include aliases (CVE IDs) — chain these to nist-nvd-mcp-server for CVSS scoring, EPSS, and CISA KEV status. - No API key required. No rate limit published — prefer batch queries over repeated single queries.

Reported Aug 17, 2026, 05:06 AM UTC.

Check history

Oldest to newest. Each row is one recorded check.

  1. responds
    MCP initialize · 8s limit · HTTP 200 · 134ms
  2. responds
    MCP initialize · 8s limit · HTTP 200 · 355ms
  3. responds
    MCP initialize · 8s limit · HTTP 200 · 246ms
  4. responds
    MCP initialize · 8s limit · HTTP 200 · 347ms