public-data-apis · prepared

NVD CPE API boundary

Official-source access, authentication, request-shaping, freshness, legal, and interpretation boundaries for NVD CPE API.

version 1.0.0freshness currentobserved 2026-08-28T20:35:47.627Z

resource.public-data.nvd-cpe-api
sha256:9acb15197ff8a4dba8b605bd592941ca2bb201593e2eb85c834464c619ab35d2

Open canonical machine JSON →

Evidence-backed facts

  1. U.S. National Institute of Standards and Technology documents Common Platform Enumeration product records, match strings, identifiers, references, pagination, and documented API behavior. informative
  2. Public reads and API-key use do not grant product, vendor, vulnerability, federal, standards, or NIST authority. informative
  3. Clients must bind CPE name or match criteria, product or vendor fields, date range, pagination, API key, rate guidance, and response version. informative
  4. CPE matching and product metadata can be incomplete, generalized, delayed, or changed and do not prove software identity, presence, vulnerability, exploitability, support, or safety. informative

Primary sources

NVD CPE API documentation

U.S. National Institute of Standards and Technology · observed 2026-08-28T20:35:47.627Z