Dev.to Security 🔐 Cybersecurity 👁 0 📖 3 min read

CISA's KEV catalogue has no RSS feed, so here is one (and which npm, PyPI and Maven packages are on it)

CISA's Known Exploited Vulnerabilities (KEV) catalogue is the shortest useful list in vulnerability management: 1,739 CVEs, out of the tens of thousands published every year, with reliable evidence of exploitation in the

CISA's Known Exploited Vulnerabilities (KEV) catalogue is the shortest useful list in vulnerability management: 1,739 CVEs, out of the tens of thousands published every year, with reliable evidence of exploitation in the wild. If one of them is in something you ship, it goes to the top of the queue.

Two things about it kept getting in my way:

  1. There is no feed. CISA publishes the catalogue as a JSON file and a CSV file. Fine for scripts, but nothing a feed reader, Slack's RSS app or an RSS-to-email service can subscribe to.
  2. It names vendors, not packages. An entry says "Vite Vitejs Improper Access Control". Your lockfile says vite 4.5.0. Joining the two means looking every CVE up in an advisory database.

So I built both and put them online. Free, no key, no account.

Atom feeds

The open-source join, as JSON

https://crawatch.dev/kev/packages.json has, for each entry, the CVE, CISA's dates and ransomware flag, the GitHub advisory, and every package it names with the affected range and the fixed versions. CORS is open.

# every npm package on the KEV list, with the fix
curl -s https://crawatch.dev/kev/packages.json \
  | jq -r '.entries[] | .packages[] | select(.ecosystem == "npm") | "\(.name) \(.range) fixed: \(.fixed)"'

Today that is 45 CVEs across 107 packages. In 2026 alone the list took in litellm, langflow, mlflow, ray, marimo and starlette on the Python side, and vite and Strapi on npm. Each CVE has its own page with the affected versions and the fix, for example CVE-2025-31125 in vite, and there is a list per ecosystem: npm, PyPI, Maven.

How the join works

For each KEV entry, look the CVE up in OSV.dev. The CVE record lists its aliases (GHSA-…, PYSEC-…), and the GitHub or PyPA advisory names the package, the ecosystem and the affected ranges:

curl -s https://api.osv.dev/v1/vulns/CVE-2025-31125 | jq '.aliases'
# [ "GHSA-4r4m-qw57-chr8" ]
curl -s https://api.osv.dev/v1/vulns/GHSA-4r4m-qw57-chr8 | jq '.affected[].package'

A Cloudflare Worker does this every hour for new entries and re-reads three older ones a day, so ranges stay current when an advisory gains a new fixed version. Entries for appliances and operating systems are left out on purpose: no lockfile carries them, and CISA and NVD already list them.

Checking your own lockfile

If you would rather check than read: paste a lockfile at https://crawatch.dev/scan (19 formats, no account), run npx crawatch package-lock.json, or add the GitHub Action, which fails a build when a dependency is on the list.

Why I built it

I make CRA Watch, a tool for the EU Cyber Resilience Act. Since 11 September 2026, a company that sells software in the EU has to tell ENISA within 24 hours when it becomes aware of an actively exploited vulnerability in its product, and for most software that vulnerability arrives through a dependency. The paid part of CRA Watch watches a lockfile against this list every day; the feeds, the JSON and the scan are free and will stay free.

Corrections welcome, especially if you spot a package that should be on the list and is not.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.