# CERT/CC Vulnerability Notes API

**Canonical:** https://apis.io/apis/carnegie-mellon-university/cert-vulnerability-notes/  
**Provider:** Carnegie Mellon University — https://apis.io/providers/carnegie-mellon-university/  
**Base URL:** https://kb.cert.org/vuls/api  
**Documentation:** https://www.kb.cert.org/vuls/

CERT/CC Vulnerability Notes API is one of 7 APIs that [Carnegie Mellon University](https://apis.io/providers/carnegie-mellon-university/) publishes on the [APIs.io](https://apis.io/) network, described by a machine-readable OpenAPI specification. This API exposes 1 JSON Schema definition. Tagged areas include Cybersecurity, Vulnerability Disclosure, CVE, Research, and Open Data. The published artifact set on APIs.io includes an OpenAPI specification, API documentation, an API reference, and 1 JSON Schema.

Public read API for the CERT Coordination Center's Vulnerability Notes database, operated by the CERT Division of the Software Engineering Institute — a federally funded research and development center operated by Carnegie Mellon University. Returns the full Note record, the CVEs a coordination case covers, and the per-vendor status statements CERT/CC collected during disclosure. The vendor-statement collection is the machine-readable trace of the coordination process itself and has no equivalent anywhere else. kb.cert.org is not a cmu.edu host, which is why the cohort audit could not see it: cert.org 301s to sei.cmu.edu, and the sibling Atom feed declares its author uri as https://www.sei.cmu.edu.

## Machine-readable artifacts (5)

- **OpenAPI** — https://raw.githubusercontent.com/api-evangelist/carnegie-mellon-university/refs/heads/main/openapi/carnegie-mellon-university-cert-vulnerability-notes-openapi.yml
- **Documentation** — https://certcc.github.io/
- **APIReference** — https://www.kb.cert.org/vuls/
- **SourceCode** — https://github.com/CERTCC
- **JSONSchema** — https://raw.githubusercontent.com/api-evangelist/carnegie-mellon-university/refs/heads/main/json-schema/carnegie-mellon-university-cert-vulnerability-note.json

## Other Carnegie Mellon University APIs (6)

- [Delphi Epidata API](https://apis.io/apis/carnegie-mellon-university/delphi-epidata/)
- [CMU Library Publishing Service API + OAI-PMH](https://apis.io/apis/carnegie-mellon-university/library-publishing/)
- [CMU Web Login (Shibboleth SAML 2.0 Identity Provider)](https://apis.io/apis/carnegie-mellon-university/web-login-sso/)
- [KiltHub Institutional Repository (figshare) — tenant](https://apis.io/apis/carnegie-mellon-university/kilthub-figshare-tenant/)
- [Canvas LTI 1.3 Advantage (Instructure) — tenant](https://apis.io/apis/carnegie-mellon-university/canvas-lti-tenant/)
- [CMU Eats API (ScottyLabs) — student-operated](https://apis.io/apis/carnegie-mellon-university/cmu-eats-scottylabs/)

## Tags

Cybersecurity, Vulnerability Disclosure, CVE, Research, Open Data

---

Profiled by [API Evangelist](https://apievangelist.com) and published on [APIs.io](https://apis.io/apis/carnegie-mellon-university/cert-vulnerability-notes/). The API's provider profile, Kin Score and agent-readiness rating are at https://apis.io/providers/carnegie-mellon-university/.
