$npx skillfedfor your agent

nvdlib

National Vulnerability Database CPE/CVE API Library for Python

With conditionsPyPI SecurityReleased Aug 2025169.2K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — nvdlib-0.8.3-py3-none-any.whl
v0.8.3 · released 2025-08-06 · Python >=3.11.0 · 1 runtime deps: requests

Yes, if you need programmatic access to NIST vulnerability data. The library has low install friction, permissive licensing, and no known vulnerabilities. The aging maintenance status (last commit 373 days ago) is a minor concern but not a blocker since the NVD API itself is stable. Requires Python 3.11.0+. Get a free NIST API key to avoid the 6-second default rate limit.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.11.0 or later.
  • NIST NVD API key recommended for faster rate limiting (default is 6 seconds between requests).
  • Low install friction with a single runtime dependency (requests).

License · maintenance · safety

MIT (permissive) — MIT license permits unrestricted use, modification, and distribution with minimal obligations—suitable for commercial and private projects.

last release 2025-08-06 (373 days) · last repo commit 2025-08-06 · 115 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 169,221 downloads/mo, #10,426 on PyPI

Verify before relying

pip install nvdlib

import nvdlib
r = nvdlib.searchCVE(cveId='CVE-2021-26855')[0]
print(r.v31severity, r.v31score)
  • Whether the library supports all NVD API v2 parameters beyond the examples shown in the description.
  • Current state of CPE search functionality and whether it reliably retrieves associated CVE IDs.
  • Performance characteristics when querying large result sets or running repeated searches.
Same gist for agents: .md · .json

What it is and what it does

NVDlib is a Python wrapper around the NIST National Vulnerability Database API that lets you query CVEs and CPEs programmatically and work with the results as structured Python objects. It handles the HTTP communication with the NVD, parses responses, and enforces rate limiting according to NIST recommendations—6 seconds between requests by default, or faster with an API key. The library supports searching CVEs by ID, keywords, severity, CVSS score, publication date, and CPE name, as well as searching CPE records and retrieving associated vulnerability IDs.

The package is designed for developers who need to integrate vulnerability data into security tools, compliance workflows, or risk assessment pipelines. It abstracts away the details of the NVD API protocol and response format, letting you focus on the security logic. The built-in rate limiting means you can run queries without manually managing delays, though you'll need a free API key from NIST to get the faster rate.

Use it for

  • Scan a list of installed packages against the NVD to identify known CVEs affecting your software supply chain.
  • Build a security dashboard that retrieves and displays the latest high-severity vulnerabilities by keyword or CPE.
  • Automate compliance checks by querying CVE severity scores and CVSS vectors for risk assessment reports.
  • Integrate vulnerability data into a CI/CD pipeline to flag dependencies with critical security issues.
  • Research a specific CVE by ID to pull its full description, severity rating, and affected CPE names.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, if you need programmatic access to NIST vulnerability data.

The library has low install friction, permissive licensing, and no known vulnerabilities. The aging maintenance status (last commit 373 days ago) is a minor concern but not a blocker since the NVD API itself is stable. Requires Python 3.11.0+. Get a free NIST API key to avoid the 6-second default rate limit.

Install

nvdlib on PyPI

Before you install

Low install friction with a single runtime dependency (requests). Maintenance status is aging—last commit was 2025-08-06, over 373 days from release, though the repository remains active and not archived.

Requires Python 3.11.0 or later. NIST NVD API key recommended for faster rate limiting (default is 6 seconds between requests).

License in practice

MIT license permits unrestricted use, modification, and distribution with minimal obligations—suitable for commercial and private projects.

Quickstart

pip install nvdlib

import nvdlib
r = nvdlib.searchCVE(cveId='CVE-2021-26855')[0]
print(r.v31severity, r.v31score)

Verify before relying

  • Whether the library supports all NVD API v2 parameters beyond the examples shown in the description.
  • Current state of CPE search functionality and whether it reliably retrieves associated CVE IDs.
  • Performance characteristics when querying large result sets or running repeated searches.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.11.0
Install frictionLow. Pure-Python wheel
Runtime dependencies
1 package
requests
MaintenanceAging 373 days since the last release
Last repo commit
First released
Downloads169,221 / month, #10,426 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: nvdlib-0.8.3-py3-none-any.whl

Tags

Capabilities
NIST NVD API wrapperCVE vulnerability lookupCPE search libraryvulnerability database clientNIST vulnerability dataCVE severity scoringsecurity vulnerability API
Topics
vulnerability-managementsecurity-scanningnist-nvd

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “NIST NVD API wrapper”

  • nvdlibWrapper library for the NIST National Vulnerability Database API that…
  • janafSearches and parses NIST-JANAF thermochemical tables into polars…
  • pysha3Provides SHA-3, SHAKE, and Keccak hash functions for Python 2.7…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also cpe · cvss · cwe2 · pysnyk · uv-secure · pysentry-rs · ca9 · debsecan-mcp · pip-audit · python-nmap