Advisory aliases
The dossier is keyed by CVE. An agent that starts from a GitHub advisory, a RustSec id or a Debian security announcement needs the CVE first, and until now the only way to it was full text search, which is the wrong machinery for a key. This endpoint reads the search index by key and answers with the CVEs an id names and every other id known for the same flaw, one hop out.
GET /api/v1/aliases/{id}{id} is any advisory identifier the index keys: CVE, GHSA, RUSTSEC, PYSEC, GO, OSV, MAL, DSA, DLA and USN, plus the redistributor families such as CGA, MINI, BELL, RHSA and SUSE. Case does not matter.
curl https://api.vulnpatch.dev/api/v1/aliases/GHSA-jfh8-c2jp-5v3qResponse
EUVD records
GET /api/v1/aliases/EUVD-2026-35189 reads that exact record from ENISA, with a one-hour cache. It links only the CVE and GHSA identifiers ENISA explicitly reports. EUVD and CVE numeric suffixes are independent: EUVD-2026-35189 names CVE-2026-11559, not the separate OpenSSL record CVE-2026-35189.
The response adds record and provenance, including the official source URL and retrieval time. reportedPublishedAt and reportedUpdatedAt preserve ENISA's date strings. Normalized dates remain null when the source does not specify a timezone. Live ENISA lookup is preferred. If ENISA is unavailable, a verified archived copy may answer; the EUVD archive backfill is in progress, so no archived match is not evidence of absence. Ambiguous CVE aliases are not guessed from the archive. /api/v1/status reports dated backfill coverage.
An exact CVE dossier also checks ENISA by CVE ID. When ENISA explicitly reports that CVE as an alias, its distinct EUVD record, reported products and linked advisories appear in the optional euvd block and their safe URLs are included in references. The euvd provenance entry distinguishes data, an empty check and an unreachable source. These claims do not override the canonical CVE, NVD or vendor fields.
Exact EUVD identifiers also work in unfiltered keyword search. Source and ecosystem filters continue to query the indexed corpora, not ENISA. Invalid identifiers return 400 EUVD_INVALID, an explicit missing record returns 404 EUVD_NOT_FOUND, and an unavailable or invalid upstream response returns 503 EUVD_UNAVAILABLE when neither ENISA nor a verified archive copy can answer. An outage never means the identifier is absent.
{
"success": true,
"data": {
"id": "GHSA-JFH8-C2JP-5V3Q",
"cves": ["CVE-2021-44228"],
"aliases": ["CVE-2021-44228", "GHSA-jfh8-c2jp-5v3q"],
"advisories": [
{
"id": "GHSA-jfh8-c2jp-5v3q",
"source": "Maven",
"aliases": ["CVE-2021-44228"],
"cves": ["CVE-2021-44228"]
}
],
"truncated": false,
"dossiers": {
"CVE-2021-44228": "https://api.vulnpatch.dev/api/v1/cve/CVE-2021-44228/dossier"
}
},
"timestamp": "2026-09-27T12:00:00.000Z"
}cves: every CVE the matching advisories name, whether as an alias or as the upstream a distribution notice repackages. Container distributions (Chainguard, MinimOS, BellSoft) publish no alias list at all, and their CVE is reached through that upstream link.aliases: every other identifier reachable in one hop. It never contains the id asked about.advisories: the index rows keyed by the id, at most one hundred. A CVE repackaged by many distributions can key more than that, andtruncatedsays when the list was cut.dossiers: a dossier URL for each CVE, which is the document to read next.
Three answers, kept apart
| Status | Code | Meaning |
|---|---|---|
| 200 | The id resolves in the index. | |
| 400 | NOT_AN_ADVISORY_ID | The path segment is not shaped like an identifier, or is a malformed member of a known family (CVE-21-44228). Nothing was looked up. |
| 404 | NOT_INDEXED | The index has no row for the id. This is a fact about the index, which holds the OSV corpora and the redistributor notices. For a CVE id, links.dossier in the body still points at the dossier, which draws on sources the index does not. |
| 503 | INDEX_UNAVAILABLE | The index could not be read. This says nothing about the id, and a client must not read it as 404. reason names the failure and the response is never cached. |
From the dossier
The dossier's canonical.aliases lists the ids its own sources file the CVE under: the GitHub advisory's GHSA id and the OSV record's id and aliases. That costs no extra read and is empty when those sources list none, not when none exist. links.aliases points at this endpoint for the answer across the whole index.
Related
- CVE Lookup
- Agent Support
- Search CVEs, which also resolves a typed identifier by key before falling back to full text